E2EE Group Chat Equivocation

Arxiv pdf 2026-07-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

End-to-end encrypted (E2EE) messaging apps are widely praised for their security and thus also used for sensitive coordination in group chats (e.g., by political decision makers). After Threema and WhatsApp, also Signal and iMessage have recently introduced polls to aid agreement processes in groups. This implicitly sets the expectation that all participants see the same outcome and thus have the same view of the conversation. This property is commonly referred to as _transcript consistency_ (TC). In this work, we demonstrate that todays major E2EE messengers do not guarantee _any_ form of TC for group chats, allowing a malicious group member to selectively omit, reorder, or present altered content to different recipients without triggering warnings in their user interface. We systematically investigate the extent of the problem under a _malicious-participant_ threat model that targets the integrity of the shared transcript, or inconsistent delivery across a users linked devices. We identify multiple equivocation vectors that range from protocol fallback paths to deliberate use of pairwise delivery channels within groups. We demonstrate concrete exploitation scenarios such as social engineering, evading moderation, and, in particular, _rigging polls_ . Beyond these cross-service design issues, we also uncover implementationspecific behaviors with privacy implications (e.g., device OS fingerprinting). Finally, we contextualize our findings within prior transcript-consistency research and outline practical lowoverhead mitigations and UI signaling strategies that can be integrated into state-of-the-art E2EE group protocols.

Loading executive summary...

LINK COPIED TO CLIPBOARD