Fun

‘High-risk’ Telegram vulnerability exposes users to attacks — CertiK

News Feed - 2024-04-09 07:04:10

Helen Partz13 hours ago‘High-risk’ Telegram vulnerability exposes users to attacks — CertiKThe newly discovered Telegram vulnerability can be avoided by disabling the automatic downloading of media files on Telegram Desktop.4680 Total views23 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksUpdate April 9, 2:40 pm UTC: Telegram denied the existence of RCE vulnerability for Telegram clients, while some security experts claimed it"s been a known issue.


A major vulnerability on Telegram messenger is exposing users to malicious attacks, according to a new report released by the blockchain security firm CertiK.


CertiK Alert took to the social media platform X on April 9 to warn the public against a “high-risk vulnerability in the wild,” potentially allowing hackers to deploy a remote code execution (RCE) attack through Telegram’s media processing.


According to the post, CertiK’s team has discovered a “possible RCE” attack in Telegram’s media processing on Telegram Desktop application.


“This issue exposes users to malicious attacks through specially crafted media files, such as images or videos,” CertiK wrote.


A spokesperson for CertiK told Cointelegraph that the vulnerability is exclusive to the desktop Telegram application because mobile "does not directly execute executable programs like desktops, which generally require signatures." The representative noted that the news on the issue came from the security community.


To avoid the vulnerability, users should check their Telegram Desktop configuration and disable the auto-download feature. The feature can be disabled by going to “Settings” and then tapping on “Advanced.”Source: CertiK


“Under the ‘Automatic Media Download’ section, disable auto-download for ‘Photos’, ‘Videos’, and ‘Files’ across all chat types (Private chats, groups, and channels),” CertiK noted.


A spokesperson for Telegram told Cointelegraph that the company "can"t confirm the existence of such a vulnerability in Telegram clients."


According crypto enthusiast and grey hat SEO Yannick Eckl, the problem with automatic downloads of media files and RCE attacks in Telegram is not new. "It is a known issue in many, but obviously not all, IT-security circles," Eckl told Cointelegraph.


Telegram is a major cryptocurrency-friendly messenger that allows users to communicate and exchange files and transact cryptocurrencies like Bitcoin (BTC) and Toncoin (TON) using its custodial wallet solution called, simply, Wallet.


The “custodial” part means that Wallet doesn’t give users the private key by default but rather puts the assets in its own custody to help industry newcomers avoid self-custody responsibilities.


Related:Telegram channels eligible for 50% ad revenue, but there’s a catch


The newly discovered vulnerability on Telegram isn’t its first. In 2023, Google engineer Dan Reva found a significant bug that could allow attackers to activate the camera and microphone on laptops running macOS.Source: Dan Rehah


In 2021, a security researcher from Shielder discovered a similar media-related issue on Telegram, which reportedly allowed attackers to send modified animated stickers, which could have exposed the victims’ data.


Telegram has been actively addressing potential vulnerabilities on its app, though. Telegram’s bug bounty program has been active since 2014, offering developers and the security research community the opportunity to submit their reports and be eligible for bounties ranging from $100 to $100,000 or more, depending on the severity of the issue.


Magazine:1 in 6 new Base meme coins are scams, 91% have vulnerabilities# Business# Security# Adoption# Telegram# Messaging App# HacksAdd reaction

News Feed

Crypto exchange FTX gets nod to sell $873M of assets to repay creditors
Brayden Lindrea6 hours agoCrypto exchange FTX gets nod to sell $873M of assets to repay creditorsNearly $700 million of the $873 million trust assets allowed to be sold by FTX comes from Grayscale’s flagship product, t
Hong Kong issues generative AI guidelines for consumer protection
Arijit Sarkar46 minutes agoHong Kong issues generative AI guidelines for consumer protectionThe HKMA introduces new principles for using generative AI, emphasizing governance, transparency, and data protection in consume
US Presidential Candidate RFK Jr. Says Bitcoin Provides An ‘Escape Route’ From Financial Turmoil
US Presidential Candidate RFK Jr. Says Bitcoin Provides An ‘Escape Route’ From Financial Turmoil On Monday, Robert F. Kennedy Jr. once again cautioned the public to be wary of
Social Media Loves Cardano, But The Chart Signals Caution
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Ezra Reguerra4 hours agoDisney launches NFT platform, eye issues at ApeFest and NFT sales rise: Nifty NewsletterCointelegraph reached out to various professionals in the Web3 space to get their thoughts on the recent upw
Rakesh Upadhyay5 hours agoHBAR, OP, INJ and RUNE flash bull signals as Bitcoin price looks for stabilityBitcoin is searching for stability in the $25,000 zone. Meanwhile, HBAR, OP, INJ and RUNE price looked primed for fu
Martin Young4 hours agoAltcoins ‘bled’ as Bitcoin gained dominance in Q2: CoinGeckoExchange, DeFi and metaverse tokens were hit hard in the second quarter of 2023 while Bitcoin continued to make gains.4186 Total view
William Suberg14 hours agoBitcoin chart highlights $24.7K as analyst says ‘nothing has changed’Bitcoin has neither broken out nor down, but the status quo still includes the risk of a trip to BTC price “bearadise.
XRP Transactions Barrels Over $1 Billion To Monthly Highs, Are Whales Driving The Next Leg?
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Global Exchange LBank Starts off Brand Update Month With Logo Reveal and Diversity Video
Global Exchange LBank Starts off Brand Update Month With Logo Reveal and Diversity Video press release PRESS RELEASE.INTERNET CITY, DUBAI, Sep. 30, 2022 – Global crypto excha
Indonesian postal service launches NFT stamps
Ezra Reguerra15 hours agoIndonesian postal service launches NFT stampsIndonesia’s state-owned postal service has launched a physical postage stamp with an NFT counterpart. 1160 Total views11 Total sharesListen to arti
Defi TVL Jumps 12% Since Mid-December, Close to $25B in Bridges, Convex Gains on Curve’s Dominance
Defi TVL Jumps 12% Since Mid-December, Close to $25B in Bridges, Convex Gains on Curve"s Dominance The total value locked (TVL) in decentralized finance (defi) has risen 4% during