- End-to-end encrypted (E2EE) messaging apps are praised for security but used for sensitive group coordination, yet they lack transcript consistency (TC), allowing malicious participants to manipulate message delivery.
- Major E2EE messengers (including Signal and iMessage) do not guarantee TC for group chats, enabling selective omission, reordering, or alteration of content without user warnings.
- Multiple equivocation vectors exist, including protocol fallback paths and deliberate use of pairwise delivery channels within groups, leading to exploitation scenarios like social engineering, moderation evasion, and poll rigging.
- Implementation-specific behaviors with privacy implications, such as device OS fingerprinting, were also uncovered.