Vulnerability CVE-2021-41861


Published: 2021-10-04

Description:
The Telegram application 7.5.0 through 7.8.0 for Android does not properly implement image self-destruction, a different vulnerability than CVE-2019-16248. After approximately two to four uses of the self-destruct feature, there is a misleading UI indication that an image was deleted (on both the sender and recipient sides). The images are still present in the /Storage/Emulated/0/Telegram/Telegram Image/ directory.

Type:

NVD-CWE-noinfo

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Telegram -> Telegram 

 References:
https://telegram.org/blog/autodelete-inv2/ru#avtomaticheskoe-udalenie-soobschenii
https://desktop.telegram.org/changelog#v-2-6-23-02-21
https://habr.com/ru/post/580582/
https://pikabu.ru/story/konfidentsialnost_polzovateley_telegram_snova_narushena_predstaviteli_messendzhera_trebuyut_ne_raskryivat_podrobnostey_8511495

Copyright 2024, cxsecurity.com

 

Back to Top