Skip to main content
  1. Home
  2. Phones
  3. Mobile
  4. News

Vulnerability in Signal messaging app could let hackers track your location

Add as a preferred source on Google

A vulnerability in the secure messaging app Signal could let a bad actor track a user’s location, according to findings from cybersecurity firm Tenable.

Researcher David Wells found that he could track a user’s movements just by calling their Signal number — whether or not the user had his contact information. This could be a big problem for victims of stalking, or for activists and journalists who are trying to avoid government or law enforcement detection to leak information or act in a whistleblower capacity.

Recommended Videos

There are two aspects to the vulnerability, Wells said. One is that if two Signal users have each other as contacts, it’s possible for them to determine each other’s location and IP address by calling, even if the person being called doesn’t answer the phone.

“That feature is not well advertised, and it’s interesting that someone could disclose your location if they’re your contact,” Wells said. “That’s kind of odd.”

It turns out that even if you don’t have a person in your contacts list, they can still roughly determine your rough location just by calling you on Signal. This works even if you don’t pick up or see the call.

“Let’s say I have a burner phone and I just ring your phone, and I do it so quickly that all you see is a missed call from some number,” Wells said. It turns out that’s enough for the caller to see what DNS server your phone automatically connects to. “Usually, it’ll be somewhat near you,” Wells continued. “So I can force that DNS server [near you] to talk to me. By getting that information, I know what DNS server you’re using and I can determine your general location.”

“The core of the issue is that you’re helpless,” Wells said. Simply by calling your phone, which you can’t control, a threat actor could determine your general location.”

“It’s not like clicking on a link [as in phishing],” he said. “Anyone can do this to you.”

Image used with permission by copyright holder

Signal has reportedly already released a patch for the vulnerability via Github, but as of now, it is not yet available through any app stores.

Signal declined to publicly comment when asked about the reported vulnerability, but Wells told Digital Trends that he heard the team was working on an update that would patch the problem.

Signal recently announced it would be rolling out PIN numbers for people to use instead of phone numbers, which may help plug the security hole.

The vulnerability also has limitations. The method isn’t 100% reliable; at one point, Wells called an associate in Pennsylvania as an experiment, and the associated DNS server that responded was 400 miles away in Toronto.

“It’s very coarse,” Wells admitted.

The researcher also wasn’t able to determine a person’s specific address, for example. But when a callee’s phone connected to certain servers, he was able to see clearly what city they were in and track their daily movements.

“We’re not cracking Signal’s encryption or saying don’t use Signal. The sky isn’t falling,” he said. “But for a certain subset of people, this is going to be a problem.”

Maya Shwayder
I'm a multimedia journalist currently based in New England. I previously worked for DW News/Deutsche Welle as an anchor and…
Apple’s new Upgrade program lets you lease an iPhone, Mac, Watch, and iPad
Launched in partnership with Klarna, the new program gets you an iPhone for as little as $17.99 a month.
Apple Upgrade site on a MacBook Neo

Apple has officially launched Apple Upgrade, a leasing program that lets customers pay monthly for an iPhone, iPad, Mac, or Apple Watch instead of buying the device outright. The program went live today on Apple's website in partnership with Klarna, replacing the iPhone Upgrade Program that Apple has offered since 2015.

What you can lease and what it costs

Read more
T-Mobile says it has fixed the nationwide signal outage after hours of disruption
Bars are back. T-Mobile confirms it has fixed Monday's nationwide outage.
T-Mobile logo on iPhone

T-Mobile's Monday outage is officially over. After thousands of customers spent hours dealing with dropped signals and iPhones stuck in SOS mode, the carrier confirmed that service has been fully restored.

So what exactly happened?

Read more
Samsung may finally give the Galaxy S27 Ultra a meaningful battery boost using silicon-carbon tech
Galaxy S27 Ultra could reach 5,700mAh as Samsung explores silicon-carbon batteries
Electronics, Phone, Mobile Phone

Samsung was already rumored to be preparing a larger battery for the Galaxy S27 Ultra, while the upcoming Galaxy S27 Pro was expected to carry a 5,000mAh cell. At the time, however, there was no indication that silicon-carbon batteries were also in the works.

Samsung recently introduced the technology on the Galaxy Z Fold 8 series. A new GalaxyClub report has now revealed the alleged battery capacities of both phones, and they could represent significant upgrades by Samsung’s standards.

Read more