Fun

‘High-risk’ Telegram vulnerability exposes users to attacks — CertiK

News Feed - 2024-04-09 07:04:10

Helen Partz13 hours ago‘High-risk’ Telegram vulnerability exposes users to attacks — CertiKThe newly discovered Telegram vulnerability can be avoided by disabling the automatic downloading of media files on Telegram Desktop.4680 Total views23 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksUpdate April 9, 2:40 pm UTC: Telegram denied the existence of RCE vulnerability for Telegram clients, while some security experts claimed it"s been a known issue.


A major vulnerability on Telegram messenger is exposing users to malicious attacks, according to a new report released by the blockchain security firm CertiK.


CertiK Alert took to the social media platform X on April 9 to warn the public against a “high-risk vulnerability in the wild,” potentially allowing hackers to deploy a remote code execution (RCE) attack through Telegram’s media processing.


According to the post, CertiK’s team has discovered a “possible RCE” attack in Telegram’s media processing on Telegram Desktop application.


“This issue exposes users to malicious attacks through specially crafted media files, such as images or videos,” CertiK wrote.


A spokesperson for CertiK told Cointelegraph that the vulnerability is exclusive to the desktop Telegram application because mobile "does not directly execute executable programs like desktops, which generally require signatures." The representative noted that the news on the issue came from the security community.


To avoid the vulnerability, users should check their Telegram Desktop configuration and disable the auto-download feature. The feature can be disabled by going to “Settings” and then tapping on “Advanced.”Source: CertiK


“Under the ‘Automatic Media Download’ section, disable auto-download for ‘Photos’, ‘Videos’, and ‘Files’ across all chat types (Private chats, groups, and channels),” CertiK noted.


A spokesperson for Telegram told Cointelegraph that the company "can"t confirm the existence of such a vulnerability in Telegram clients."


According crypto enthusiast and grey hat SEO Yannick Eckl, the problem with automatic downloads of media files and RCE attacks in Telegram is not new. "It is a known issue in many, but obviously not all, IT-security circles," Eckl told Cointelegraph.


Telegram is a major cryptocurrency-friendly messenger that allows users to communicate and exchange files and transact cryptocurrencies like Bitcoin (BTC) and Toncoin (TON) using its custodial wallet solution called, simply, Wallet.


The “custodial” part means that Wallet doesn’t give users the private key by default but rather puts the assets in its own custody to help industry newcomers avoid self-custody responsibilities.


Related:Telegram channels eligible for 50% ad revenue, but there’s a catch


The newly discovered vulnerability on Telegram isn’t its first. In 2023, Google engineer Dan Reva found a significant bug that could allow attackers to activate the camera and microphone on laptops running macOS.Source: Dan Rehah


In 2021, a security researcher from Shielder discovered a similar media-related issue on Telegram, which reportedly allowed attackers to send modified animated stickers, which could have exposed the victims’ data.


Telegram has been actively addressing potential vulnerabilities on its app, though. Telegram’s bug bounty program has been active since 2014, offering developers and the security research community the opportunity to submit their reports and be eligible for bounties ranging from $100 to $100,000 or more, depending on the severity of the issue.


Magazine:1 in 6 new Base meme coins are scams, 91% have vulnerabilities# Business# Security# Adoption# Telegram# Messaging App# HacksAdd reaction

News Feed

Arijit Sarkar1 hour agoCFTC Commissioner plans to modernize investor protection with technologyTo minimize the damages caused by financial fraud, Romero proposed the formation of the National Financial Fraud Registry —
FTX creditors only getting '10-25% of their crypto back' — creditor
Vince Quill5 hours agoFTX creditors only getting "10-25% of their crypto back" — creditorFollowing the collapse of the FTX exchange, the FTT token collapsed by more than 80% and wiped away over $2 billion in customer v
Quicknode Raises $60 Million in Series B to ‘Fuel Blockchain Adoption’ and Expand Globally
Quicknode Raises $60 Million in Series B to ‘Fuel Blockchain Adoption’ and Expand Globally Web3 infrastructure firm Quicknode raised $60 million in a Series B funding round, ac
33,000 Companies in China Claim to Use Blockchain Technology
33,000 Companies in China Claim to Use Blockchain Technology China now has more than 33,000 registered companies claiming to use blockchain technology in their businesses, accord
Despite Warnings from Regulators, the Ethereum Fueled Pyramid Scheme Forsage Thrives
Despite Warnings from Regulators, the Ethereum Fueled Pyramid Scheme Forsage ThrivesWhile Ethereum has seen a number of benefits from the decentralized finance (defi) movement and i
User loses $32 million spWETH in a sophisticated phishing attack
Vince Quill3 hours agoUser loses $32 million spWETH in a sophisticated phishing attackAccording to crypto security firm Scam Sniffer, 9,145 users were victims of phishing attacks during August 2024, losing funds as a res
Derek Andersen4 hours agoChamber of Digital Commerce launches Digital Power Network miners’ coalitionThe new advocacy group already represents over half the country’s Bitcoin hash rate and will seek to shape energy p
Electronic Frontier Foundation: US Government Will Expand Financial Surveillance Through FinCEN’s Proposed Crypto Wallet Rules
Electronic Frontier Foundation: US Government Will Expand Financial Surveillance Through FinCEN"s Proposed Crypto Wallet Rules The Electronic Frontier Foundation
Arijit Sarkar1 hour agoIndian central bank-backed NPCI begins blockchain recruitmentSingapore, Malaysia, the UAE, France, Benelux countries, Nepal and the U.K. have adopted the NPCI’s UPI payments system to varying deg
Post-Shapella Hard Fork: Ethereum Deposits Exceed Withdrawals, Wait Time Climbs, ETH Transfer Fees Jump
Post-Shapella Hard Fork: Ethereum Deposits Exceed Withdrawals, Wait Time Climbs, ETH Transfer Fees Jump It has been a week since Ethereum’s Shapella hard fork, and statistic
Open Metaverse Alliance OMA3 Launches to Develop Standards for an Interoperable Digital World
Open Metaverse Alliance OMA3 Launches to Develop Standards for an Interoperable Digital World The Open Metaverse Alliance, OMA3, was launched by a group of Web3 dedicated companies
SEC Chairman Says Satoshi Nakamoto’s Innovation Is Real, Crypto Rules Are Clear
SEC Chairman Says Satoshi Nakamoto"s Innovation Is Real, Crypto Rules Are Clear The chairman of the U.S. Securities and Exchange Commission (SEC), Gary Gensler,