An incorrect implementation of XEP-0280: Message Carbons[0] in psi-plus client allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. References: http://seclists.org/oss-sec/2017/q1/373