Whisperfish beta.34
Contains two mitigations for vulnerabilities, discovered by @valldrac. Vulnerabilities will be listed as CVE-2025-24904
and CVE-2025-24903
, and could practically bypass end-to-end encryption, which means that a malicious actor could, theoretically, impersonate one of your contacts. We have no knowledge of exploits in the wild.
Changes
- Fixes for two impersonation vulnerabilities
- Preliminary parsing and linking of
geo:
-urls - Fixes for linking and registration