{"api_version":"1","generated_at":"2026-07-23T06:31:41+00:00","cve":"CVE-2018-9840","urls":{"html":"https://cve.report/CVE-2018-9840","api":"https://cve.report/api/cve/CVE-2018-9840.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-9840","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-9840"},"summary":{"title":"CVE-2018-9840","description":"The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app opening, clicking on cancel, and using the home button.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-04-10 05:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"http://nint.en.do/Signal-Bypass-Screen-locker.php","name":"http://nint.en.do/Signal-Bypass-Screen-locker.php","refsource":"MISC","tags":["Broken Link","Third Party Advisory"],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"0"},{"url":"https://github.com/signalapp/Signal-iOS/commit/018a35df7b42b4941cb4dfc9f462b37c3fafd9e9","name":"https://github.com/signalapp/Signal-iOS/commit/018a35df7b42b4941cb4dfc9f462b37c3fafd9e9","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Merge remote-tracking branch 'origin/charlesmchen/screenLockRework_' … · signalapp/Signal-iOS@018a35d · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/signalapp/Signal-iOS/commits/release/2.23.2","name":"https://github.com/signalapp/Signal-iOS/commits/release/2.23.2","refsource":"MISC","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"Commits · signalapp/Signal-iOS · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-9840","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-9840","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"9840","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"signal","cpe5":"signal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"iphone_os","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"9840","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"signal","cpe5":"signal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"iphone_os","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-9840","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app opening, clicking on cancel, and using the home button."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/signalapp/Signal-iOS/commit/018a35df7b42b4941cb4dfc9f462b37c3fafd9e9","refsource":"MISC","url":"https://github.com/signalapp/Signal-iOS/commit/018a35df7b42b4941cb4dfc9f462b37c3fafd9e9"},{"name":"https://github.com/signalapp/Signal-iOS/commits/release/2.23.2","refsource":"MISC","url":"https://github.com/signalapp/Signal-iOS/commits/release/2.23.2"},{"name":"http://nint.en.do/Signal-Bypass-Screen-locker.php","refsource":"MISC","url":"http://nint.en.do/Signal-Bypass-Screen-locker.php"}]}},"nvd":{"publishedDate":"2018-04-10 05:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.8,"baseSeverity":"MEDIUM"},"exploitabilityScore":0.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:signal:signal:*:*:*:*:*:iphone_os:*:*","versionEndExcluding":"2.23.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"9840","Ordinal":"126255","Title":"CVE-2018-9840","CVE":"CVE-2018-9840","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"9840","Ordinal":"1","NoteData":"The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app opening, clicking on cancel, and using the home button.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"9840","Ordinal":"2","NoteData":"2018-04-10","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"9840","Ordinal":"3","NoteData":"2018-04-10","Type":"Other","Title":"Modified"}]}}}