Executive brief
Soroush IM is a desktop messaging application used for private communication. A security flaw allows an attacker with physical or local access to a computer to bypass the application's passcode protection. This means an unauthorized person could unlock the app and read all private chats, view images, and access shared files without knowing the user's password.
Technical details
The Soroush IM Desktop App (v0.17.0 and earlier) utilizes a constant encryption key for its local database files. This allows a local attacker to bypass the passcode authentication mechanism by injecting pre-encrypted database records (specifically a 'NO_PASSCODE' state) into the application's data directory. The application processes these malicious entries from log files into the permanent database, effectively unlocking the client. An attacker with local filesystem access can achieve full unauthorized access to stored chats, media, and files, or perform a denial-of-service by setting a new unknown passcode.
Affected products
- Soroush Messenger Soroush IM Desktop App 0.17.0 and earlier
Timeline
- 2018-08-08: disclosed: Initial exploit code published by VortexNeoX64
- 2026-05-25: advisory: CVE-2018-25361 published/updated via VulnCheck/NVD