You would just send him a link in a Signal message. His phone number is widely known and he has Signal installed on his desktop computer.
Signal’s protocol secures the message in transit. But their desktop app may or may not have client-side vulnerabilities. And if he clicks a link, you’re out of Signal and into the browser. If the link downloads a file, you’re into the OS.
There is a Signal social engineering vulnerability where the attacker gets people to click a link that links the attacker's device to the target's Signal account.
There is a Signal social engineering vulnerability where you just happen to exist and have a Signal account and the SecDef invites you to what should be classified communications.
I don't know why people think these incompetent buffoons would need 0-day vulnerabilities to get. Trump just tweeted pictures from classified spy satellites. If you want to know a secret of America's right now, you can either purchase it for a small amount out of Trump's bathroom, or just needle him with a "I bet you don't know/have...." and he will tell you whatever you want to know as a "Brag".
At least one of the members of that chat was IN MOSCOW, I think even IN THE KREMLIN at the time.
Several Republican party leaders were in a meeting with Putin in Moscow on July 4th 2018. They aren't TRYING to keep info out of the Kremlin's hands. They are so incompetent they couldn't keep it out of Beijing's hands if they wanted to.
Signal’s protocol secures the message in transit. But their desktop app may or may not have client-side vulnerabilities. And if he clicks a link, you’re out of Signal and into the browser. If the link downloads a file, you’re into the OS.