Fun

‘High-risk’ Telegram vulnerability exposes users to attacks — CertiK

News Feed - 2024-04-09 07:04:10

Helen Partz13 hours ago‘High-risk’ Telegram vulnerability exposes users to attacks — CertiKThe newly discovered Telegram vulnerability can be avoided by disabling the automatic downloading of media files on Telegram Desktop.4680 Total views23 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksUpdate April 9, 2:40 pm UTC: Telegram denied the existence of RCE vulnerability for Telegram clients, while some security experts claimed it"s been a known issue.


A major vulnerability on Telegram messenger is exposing users to malicious attacks, according to a new report released by the blockchain security firm CertiK.


CertiK Alert took to the social media platform X on April 9 to warn the public against a “high-risk vulnerability in the wild,” potentially allowing hackers to deploy a remote code execution (RCE) attack through Telegram’s media processing.


According to the post, CertiK’s team has discovered a “possible RCE” attack in Telegram’s media processing on Telegram Desktop application.


“This issue exposes users to malicious attacks through specially crafted media files, such as images or videos,” CertiK wrote.


A spokesperson for CertiK told Cointelegraph that the vulnerability is exclusive to the desktop Telegram application because mobile "does not directly execute executable programs like desktops, which generally require signatures." The representative noted that the news on the issue came from the security community.


To avoid the vulnerability, users should check their Telegram Desktop configuration and disable the auto-download feature. The feature can be disabled by going to “Settings” and then tapping on “Advanced.”Source: CertiK


“Under the ‘Automatic Media Download’ section, disable auto-download for ‘Photos’, ‘Videos’, and ‘Files’ across all chat types (Private chats, groups, and channels),” CertiK noted.


A spokesperson for Telegram told Cointelegraph that the company "can"t confirm the existence of such a vulnerability in Telegram clients."


According crypto enthusiast and grey hat SEO Yannick Eckl, the problem with automatic downloads of media files and RCE attacks in Telegram is not new. "It is a known issue in many, but obviously not all, IT-security circles," Eckl told Cointelegraph.


Telegram is a major cryptocurrency-friendly messenger that allows users to communicate and exchange files and transact cryptocurrencies like Bitcoin (BTC) and Toncoin (TON) using its custodial wallet solution called, simply, Wallet.


The “custodial” part means that Wallet doesn’t give users the private key by default but rather puts the assets in its own custody to help industry newcomers avoid self-custody responsibilities.


Related:Telegram channels eligible for 50% ad revenue, but there’s a catch


The newly discovered vulnerability on Telegram isn’t its first. In 2023, Google engineer Dan Reva found a significant bug that could allow attackers to activate the camera and microphone on laptops running macOS.Source: Dan Rehah


In 2021, a security researcher from Shielder discovered a similar media-related issue on Telegram, which reportedly allowed attackers to send modified animated stickers, which could have exposed the victims’ data.


Telegram has been actively addressing potential vulnerabilities on its app, though. Telegram’s bug bounty program has been active since 2014, offering developers and the security research community the opportunity to submit their reports and be eligible for bounties ranging from $100 to $100,000 or more, depending on the severity of the issue.


Magazine:1 in 6 new Base meme coins are scams, 91% have vulnerabilities# Business# Security# Adoption# Telegram# Messaging App# HacksAdd reaction

News Feed

Small Business Owners Study Says Los Angeles Ranks the Most Crypto-Friendly City in the US
Small Business Owners Study Says Los Angeles Ranks the Most Crypto-Friendly City in the US A recent study conducted by the online invoicing company that works with small businesses
Anthony Clarke10 hours agoAI signals vs. human intuition: Decision-making in crypto tradingAI and human intuition together can make for powerful trading tools.1219 Total views13 Total sharesListen to article 0:00Analysis
Russia May ‘Nationalize’ Foreign Assets in Response to Western Sanctions, Medvedev Says
Russia May ‘Nationalize’ Foreign Assets in Response to Western Sanctions, Medvedev Says Authorities in Russia may begin to seize funds of foreign nationals and companies that a
Tiffany & Co. NFT Sale Sells out, Luxury Jewelry Retailer Rakes in $12.5M in Ethereum
Tiffany & Co. NFT Sale Sells out, Luxury Jewelry Retailer Rakes in $12.5M in Ethereum On August 5, 2022, the American luxury jewelry retailer Tiffany & Co. announced that the compa
MetaMask launches pilot self-custody debit card with Mastercard
Vince Quill7 hours agoMetaMask launches pilot self-custody debit card with MastercardMore than 1 billion individuals remain unbanked or lack adequate access to banking services, according to 2022 data from the World Bank
The Crypto Industry’s $400M Cash and Stock Deal – Binance to Acquire Coinmarketcap.com
The Crypto Industry’s $400M Cash and Stock Deal - Binance to Acquire Coinmarketcap.com The popular cryptocurrency exchange Binance is allegedly in talks with the owners of coin
Bitcoin, Ethereum Technical Analysis: BTC up to $30,000 to Start the Week
Bitcoin, Ethereum Technical Analysis: BTC up to $30,000 to Start the Week Bitcoin rose above $30,000 to start the week, with bearish sentiment marginally fading as we head into Jun
Cryptojacking: A Rising Threat to All Internet Users
Cryptojacking: A Rising Threat to All Internet UsersThe cryptocurrency revolution steadily marches on. While it has yet to completely reshape the financial and other systems of ever
Marathon Secures 254 Megawatts to Bolster Company’s 2023 Bitcoin Mining Goals
Marathon Secures 254 Megawatts to Bolster Company"s 2023 Bitcoin Mining Goals The bitcoin mining operation Marathon has announced the company has secured 254 megawatts of new hosti
Gareth Jenkinson11 hours agoPrivacy firm Nym launches $300M fund, eyes Web3 wallets, RPCs and infrastructure servicesThe blockchain security firm will look to support open-source projects building security and privacy to
Jesse Coghlan7 hours agoPro-Bitcoin Javier Milei trails as Argentina’s presidential election goes to run-offAnti-establishment Javier Milei was the touted favorite in Argentina’s presidential election but is trailing
ZoidPay to Revolutionize the Web3 Landscape With $75M Investment Commitment From GEM Digital
ZoidPay to Revolutionize the Web3 Landscape With $75M Investment Commitment From GEM Digital press release A $75M financial commitment is set to establish ZoidPay as the go-to open