Fun

‘High-risk’ Telegram vulnerability exposes users to attacks — CertiK

News Feed - 2024-04-09 07:04:10

Helen Partz13 hours ago‘High-risk’ Telegram vulnerability exposes users to attacks — CertiKThe newly discovered Telegram vulnerability can be avoided by disabling the automatic downloading of media files on Telegram Desktop.4680 Total views23 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksUpdate April 9, 2:40 pm UTC: Telegram denied the existence of RCE vulnerability for Telegram clients, while some security experts claimed it"s been a known issue.


A major vulnerability on Telegram messenger is exposing users to malicious attacks, according to a new report released by the blockchain security firm CertiK.


CertiK Alert took to the social media platform X on April 9 to warn the public against a “high-risk vulnerability in the wild,” potentially allowing hackers to deploy a remote code execution (RCE) attack through Telegram’s media processing.


According to the post, CertiK’s team has discovered a “possible RCE” attack in Telegram’s media processing on Telegram Desktop application.


“This issue exposes users to malicious attacks through specially crafted media files, such as images or videos,” CertiK wrote.


A spokesperson for CertiK told Cointelegraph that the vulnerability is exclusive to the desktop Telegram application because mobile "does not directly execute executable programs like desktops, which generally require signatures." The representative noted that the news on the issue came from the security community.


To avoid the vulnerability, users should check their Telegram Desktop configuration and disable the auto-download feature. The feature can be disabled by going to “Settings” and then tapping on “Advanced.”Source: CertiK


“Under the ‘Automatic Media Download’ section, disable auto-download for ‘Photos’, ‘Videos’, and ‘Files’ across all chat types (Private chats, groups, and channels),” CertiK noted.


A spokesperson for Telegram told Cointelegraph that the company "can"t confirm the existence of such a vulnerability in Telegram clients."


According crypto enthusiast and grey hat SEO Yannick Eckl, the problem with automatic downloads of media files and RCE attacks in Telegram is not new. "It is a known issue in many, but obviously not all, IT-security circles," Eckl told Cointelegraph.


Telegram is a major cryptocurrency-friendly messenger that allows users to communicate and exchange files and transact cryptocurrencies like Bitcoin (BTC) and Toncoin (TON) using its custodial wallet solution called, simply, Wallet.


The “custodial” part means that Wallet doesn’t give users the private key by default but rather puts the assets in its own custody to help industry newcomers avoid self-custody responsibilities.


Related:Telegram channels eligible for 50% ad revenue, but there’s a catch


The newly discovered vulnerability on Telegram isn’t its first. In 2023, Google engineer Dan Reva found a significant bug that could allow attackers to activate the camera and microphone on laptops running macOS.Source: Dan Rehah


In 2021, a security researcher from Shielder discovered a similar media-related issue on Telegram, which reportedly allowed attackers to send modified animated stickers, which could have exposed the victims’ data.


Telegram has been actively addressing potential vulnerabilities on its app, though. Telegram’s bug bounty program has been active since 2014, offering developers and the security research community the opportunity to submit their reports and be eligible for bounties ranging from $100 to $100,000 or more, depending on the severity of the issue.


Magazine:1 in 6 new Base meme coins are scams, 91% have vulnerabilities# Business# Security# Adoption# Telegram# Messaging App# HacksAdd reaction

News Feed

BlackRock Bitcoin ETF inflows surpass 'magnificent 7' stocks as trader eyes $88K
Zoltan Vardai50 minutes agoBlackRock Bitcoin ETF inflows surpass "magnificent 7" stocks as trader eyes $88KBitcoin price could reach above the $88,000 mark by September, driven by continued Bitcoin ETF inflows.485 Total
Kim Dotcom’s Planned Token Sale Is Off, Says Bitfinex
Bitfinex and a blockchain project launched by Kim Dotcom have “mutually agreed” to part ways, scuppering a planned initial exchange offering (IEO) for the controversial internet entrepreneur.
New York Watchdog Extends Window for Bittrex Users to Withdraw Funds
Crypto exchange Bittrex will once again extend its deadline for New York customers to withdraw funds from their accounts following approval from the New York Department of Financial Services (NYDFS).
Borderlands 3 Proves the Most Powerful Weapon Is FOMO
Gamers and reviewers alike are gushing over Borderlands 3. | Source: 2K GamesFresh off a promotional run peppered with successive controversies, Borderlands 3 is finally out, and pl
As BTC Slides Toward Resistance, the Chance of a Rare Triple Top Formation Comes Into Play
As BTC Slides Toward Resistance, the Chance of a Rare Triple Top Formation Comes Into Play The cryptocurrency economy has shed a lot of value during the last six months dropping 48
William Suberg13 hours agoBitcoin halving to raise ‘efficient’ BTC mining costs to $30KBitcoin miners may see “severe” economic consequences from BTC price action staying below $30,000 after the 2024 halving, Gla
Jesse Coghlan3 hours agoSam Bankman-Fried seeks expert to counter testimony from DOJ witnessesFormer FTX CEO Sam Bankman-Fried intends to call on a financial expert to rebuff testimonies from Caroline Ellison, Gary Wang,
Hong Kong Judge Rules Crypto Assets as ‘Property,’ Following Similar Rulings Worldwide
Hong Kong Judge Rules Crypto Assets as ‘Property,’ Following Similar Rulings Worldwide In a court case linked to the now-defunct crypto exchange Gatecoin, a Hong Kong judge has
Get 5x Verse Tokens in Bitcoin.com Games’ Exclusive Raffle for Players Participating in the Verse Public Sale
Get 5x Verse Tokens in Bitcoin.com Games’ Exclusive Raffle for Players Participating in the Verse Public Sale Participate in the Verse Public sale and opt into the exclusive raff
William Suberg11 hours agoBitcoin traders hope to ‘buy the dip’ as BTC price heads toward $30KBTC price action teases a slow comedown to support, with Bitcoin dip-buyers at the ready.3365 Total views3 Total sharesLis
Ethereum traders turn bearish as ETH price dips under $3K
Marcel Pechman4 hours agoEthereum traders turn bearish as ETH price dips under $3KETH price dropped to a multi-month low but ETH derivatives data suggests that traders believe the correction is over.1986 Total views72 To
Ripple Extends Banking Network With Finastra Partnership
Payment network Ripple announced Wednesday its collaboration with fintech firm Finastra. Using Ripple’s blockchain-based platform, Finastra users can now connect with the