Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the Discord libdave library could allow an attacker to add an unauthorized member to encrypted voice and video sessions. This could compromise the confidentiality and integrity of communications.
- Unauthorized members can join encrypted sessions.
- Protects end-to-end encrypted media session integrity.
- Confirm if this library is used within the organization.
Attack Path
How an attacker could exploit the issue
An attacker controlling the signaling path for Discord's libdave, such as a voice gateway, can manipulate messages to add an unauthorized participant to an encrypted call. This bypasses security checks, allowing the attacker to eavesdrop on or tamper with the audio and video conversations.
- Entry requires control over signaling messages.
- Triggered by sending a specific welcome message.
- Compromises call confidentiality and integrity.
Live Threat
Current exploitation, exposure, and threat context
An attacker on the DAVE signaling path could add an unauthorized participant to an encrypted voice or video session. This could compromise the confidentiality and integrity of the media stream.
- Encrypted media sessions.
- Unrecognized participant in group roster.
- Compromised confidentiality and integrity.
Operational Fix
Recommended remediation, mitigation, and detection steps
The libdave library's handling of unrecognized participants in MLS Welcome messages presents a risk to the confidentiality and integrity of encrypted media sessions. Teams responsible for managing the voice gateway or equivalent signaling path, along with application owners integrating libdave, should prioritize assessing exposure. The immediate first step is to identify all instances of the affected technology, determine their reachability and criticality, and then identify the accountable owner to plan remediation based on risk.
- Application and platform owners own this issue.
- Verify signaling path reachability and criticality.
- Plan remediation based on identified risk.