Fun

‘High-risk’ Telegram vulnerability exposes users to attacks — CertiK

News Feed - 2024-04-09 07:04:10

Helen Partz13 hours ago‘High-risk’ Telegram vulnerability exposes users to attacks — CertiKThe newly discovered Telegram vulnerability can be avoided by disabling the automatic downloading of media files on Telegram Desktop.4680 Total views23 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksUpdate April 9, 2:40 pm UTC: Telegram denied the existence of RCE vulnerability for Telegram clients, while some security experts claimed it"s been a known issue.


A major vulnerability on Telegram messenger is exposing users to malicious attacks, according to a new report released by the blockchain security firm CertiK.


CertiK Alert took to the social media platform X on April 9 to warn the public against a “high-risk vulnerability in the wild,” potentially allowing hackers to deploy a remote code execution (RCE) attack through Telegram’s media processing.


According to the post, CertiK’s team has discovered a “possible RCE” attack in Telegram’s media processing on Telegram Desktop application.


“This issue exposes users to malicious attacks through specially crafted media files, such as images or videos,” CertiK wrote.


A spokesperson for CertiK told Cointelegraph that the vulnerability is exclusive to the desktop Telegram application because mobile "does not directly execute executable programs like desktops, which generally require signatures." The representative noted that the news on the issue came from the security community.


To avoid the vulnerability, users should check their Telegram Desktop configuration and disable the auto-download feature. The feature can be disabled by going to “Settings” and then tapping on “Advanced.”Source: CertiK


“Under the ‘Automatic Media Download’ section, disable auto-download for ‘Photos’, ‘Videos’, and ‘Files’ across all chat types (Private chats, groups, and channels),” CertiK noted.


A spokesperson for Telegram told Cointelegraph that the company "can"t confirm the existence of such a vulnerability in Telegram clients."


According crypto enthusiast and grey hat SEO Yannick Eckl, the problem with automatic downloads of media files and RCE attacks in Telegram is not new. "It is a known issue in many, but obviously not all, IT-security circles," Eckl told Cointelegraph.


Telegram is a major cryptocurrency-friendly messenger that allows users to communicate and exchange files and transact cryptocurrencies like Bitcoin (BTC) and Toncoin (TON) using its custodial wallet solution called, simply, Wallet.


The “custodial” part means that Wallet doesn’t give users the private key by default but rather puts the assets in its own custody to help industry newcomers avoid self-custody responsibilities.


Related:Telegram channels eligible for 50% ad revenue, but there’s a catch


The newly discovered vulnerability on Telegram isn’t its first. In 2023, Google engineer Dan Reva found a significant bug that could allow attackers to activate the camera and microphone on laptops running macOS.Source: Dan Rehah


In 2021, a security researcher from Shielder discovered a similar media-related issue on Telegram, which reportedly allowed attackers to send modified animated stickers, which could have exposed the victims’ data.


Telegram has been actively addressing potential vulnerabilities on its app, though. Telegram’s bug bounty program has been active since 2014, offering developers and the security research community the opportunity to submit their reports and be eligible for bounties ranging from $100 to $100,000 or more, depending on the severity of the issue.


Magazine:1 in 6 new Base meme coins are scams, 91% have vulnerabilities# Business# Security# Adoption# Telegram# Messaging App# HacksAdd reaction

News Feed

25% of South Africans Own Cryptocurrency With Average Value of Assets Held Below $70
25% of South Africans Own Cryptocurrency With Average Value of Assets Held Below $70 According to the findings of a study by KLA, a market research and data specialist firm, some 4
Grayscale introduces crypto investment fund that prioritizes staking rewards
Ciaran Lyons3 hours agoGrayscale introduces crypto investment fund that prioritizes staking rewardsInvestors must have assets under management exceeding $1.1 million or a net worth over $2.2 million to qualify for Graysc
$2K per Month for Every American: Andrew Yang Begs Congress to Pass Basic Income
$2K per Month for Every American: Andrew Yang Begs Congress to Pass Basic Income While most of the U.S. remains on lockdown, a few states across the nation are starting to open up b
Turkish Lira Slump Contributes to Rise in Turkey’s Daily Crypto Trades to Over One Million
Turkish Lira Slump Contributes to Rise in Turkey"s Daily Crypto Trades to Over One Million The popularity of cryptocurrencies in economically embattled Turkey has continued to surg
Bitcoin Faces Major Deleveraging – Analyst Explains Price Crash Below $100K
Este artículo también está disponible en español. Bitcoin experienced significant selling pressure after successfully breaking above the $100K mark, a psychological miles
Hong Kong green lights first spot Bitcoin ETFs: Law Decoded
David Attlee4 hours agoHong Kong green lights first spot Bitcoin ETFs: Law DecodedThe new ETFs are reportedly from Harvest Global Investments, China Asset Management and a partnership between HashKey and Bosera Asset Man
Jon Rice3 hours agoPay-to-use blockchains will never achieve mass adoptionBlockchain projects should learn from Google and Facebook by monetizing their users without directly asking for their money.1645 Total views16 Tot
Crypto Businesses Ask 27 EU Finance Ministers to Loosen Disclosure Requirements
Crypto Businesses Ask 27 EU Finance Ministers to Loosen Disclosure Requirements Forty-six European crypto businesses and organizations have asked finance ministers in 27 European c
Bitcoin Hits $50K, Crypto Asset Jumps 200% in 3 Months, USD Shorts Touch a Decade High
Bitcoin Hits $50K, Crypto Asset Jumps 200% in 3 Months, USD Shorts Touch a Decade High The price of bitcoin touched an all-time high surpassing the $50k handle o
Register Here for a Weekly Update on African News
Register Here for a Weekly Update on African News The African continent may not be the biggest crypto/blockchain market yet but the growing adoption of the technology illustrates t
Trader claims to lose $310K on dodgy exchange pitched in LinkedIn request
Felix Ng4 hours agoTrader claims to lose $310K on dodgy exchange pitched in LinkedIn requestThe investor said they learned about the exchange from a “random friend request on LinkedIn.”1112 Total views2 Total sharesL
Ethereum Price Maintains Movement Inside Ascending Triangle, Is Another Crash Coming?
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu