There's a new feature to sync old messages that seems like it could potentially make that attack vector ten times worse:
https://www.bleepingcomputer.com/news/security/signal-will-l...
Would a malicious URL be able to activate this feature as part of the request?