Ignore expireTimerVersion=0 messages
Fixed in: v8.5.0
details
- Finding IDs
- F-SIGNAL-DESKTOP-EXPIRE-001
- Status
- fixed publicly
- Fixed in
- v8.5.0
- Reported via
- security contact
- Note
- A zero expiration-timer version could enter conversation timer-state handling instead of being rejected as an invalid version. The public fix chain began with serialization changes on 10 March 2026; commit c863dfa6 of 20 March adds the explicit version === 0 rejection. That check is present in stable v8.5.0, not just the previously recorded 8.10.0 alpha; inspected v8.4.1 still lacks it. This addresses the zero-version state-update path, not a guarantee that conversation participants cannot legitimately change a disappearing-message timer. Source and release inspection do not establish rollout to every desktop installation.
F-SIGNAL-DESKTOP-EXPIRE-001: Input / state handling. Expiration-state handling fails to enforce the intended version cutoff. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-SIGNAL-DESKTOP-EXPIRE-001
Security area (1seal assessment): Integrity. Rejecting zero or stale expiration-timer versions preserves the ordering and integrity of conversation timer state. Reviewed 26 Sep 2026.