Vulnerability record · CVE-2025-47729 · published 8 May 2025
CVE-2025-47729: TeleMessage archiving backend stores cleartext message copies
Telemessage · Text Message Archiver
The TeleMessage archiving backend through 2025-05-05 retains cleartext copies of messages from TM SGNL (Archive Signal) app users, contradicting the documented end-to-end encryption from mobile phone to corporate archive. This hidden functionality means messages users believed were encrypted are readable at the archive, and it was exploited in the wild in May 2025.
Description
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityIt is in CISA KEV with confirmed in-the-wild exploitation, though the CVSS score is medium and requires high privileges.
What it is
The TeleMessage archiving backend through 2025-05-05 retains cleartext copies of messages from TM SGNL (Archive Signal) app users, contradicting the documented end-to-end encryption from mobile phone to corporate archive. This hidden functionality means messages users believed were encrypted are readable at the archive, and it was exploited in the wild in May 2025.
Impact
An attacker with access to the backend or its stored data gains cleartext message content that was expected to remain end-to-end encrypted. This exposes sensitive communications of TM SGNL users.
Attack surface
The flaw is in the archiving backend, reachable over the network (AV:N) and requiring high privileges (PR:H) per the CVSS vector; no user interaction is needed. The record does not detail the exact access path or whether authentication beyond the stated privilege level is required.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2025-05-12, confirming active exploitation in the wild in May 2025. EPSS is low (0.00428, 36th percentile), and references are press coverage plus the CISA KEV entry.
What to do
- Apply vendor mitigations per TeleMessage instructions or discontinue use of the product if mitigations are unavailable, as directed by CISA KEV.
- Follow applicable BOD 22-01 guidance for cloud services.
- Audit the archiving backend for cleartext message storage and remove or encrypt retained copies.
- Restrict network and privileged access to the archiving backend to the minimum necessary.
- Review TM SGNL deployment against the documented end-to-end encryption claims and reassess trust in the archive.
Detection
- Hunt for cleartext message content in TeleMessage archive storage or backups.
- Monitor privileged access to the archiving backend for anomalous or unauthorized retrieval.
- Review network logs for unexpected connections to the archiving backend.
- Check for vendor advisories or indicators tied to the May 2025 exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-47729 to the Known Exploited Vulnerabilities catalog on 12 May 2025 as "TeleMessage TM SGNL Hidden Functionality Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 2 June 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://arstechnica.com/security/2025/05/signal-clone-used-by-trump-official-stops-operations-after-report-it-was-hacked | Press/Media Coverage |
| https://news.ycombinator.com/item?id=43909220 | Press/Media Coverage |
| https://www.theregister.com/2025/05/05/telemessage_investigating/ | Press/Media Coverage |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-47729 | US Government Resource |
Track CVE-2025-47729 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-47729), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.