Currencies28561
Market Cap$ 2.25T-3.17%
24h Spot Volume$ 63.30B-0.03%
BTC Dominance50.25%-1.24%
ETH Gas6 Gwei
Cryptorank
CryptoRankNewsTelegram deb...

Telegram debunks reported vulnerability in desktop app, confirms mobile security


Telegram debunks reported vulnerability in desktop app, confirms mobile security
Apr, 09, 2024
1 min read
by CryptoSlate
Telegram debunks reported vulnerability in desktop app, confirms mobile security

The crypto-friendly messaging application Telegram has debunked claims that a vulnerability on its platform exposed its users to attacks.

The alleged vulnerability

Blockchain security firm CertiK said on April 9 that Telegram’s desktop application has a potential high-risk Remote Code Execution (RCE) vulnerability. The firm stated:

“Possible RCE detected in Telegram’s media processing in the Telegram Desktop application. This issue exposes users to malicious attacks through specially crafted media files, such as images or videos.”

According to CertiK, this vulnerability could allow malicious actors to send RCE to users, potentially exposing them to attacks via specially crafted media files.

The security firm clarified that the vulnerability is confined to desktop apps, which can execute programs contained within files. Mobile applications remain unaffected, as they do not execute programs.

CertiK advised users to deactivate the auto-download feature on the desktop application for security purposes. Users can adjust their media download settings to manual downloads in the app’s settings.

Telegram’s response

In an April 9 post on X (formerly Twitter), Telegram stated that the trending videos were likely a hoax as there was no such vulnerability on its platform.

Nevertheless, the platform urged users to report any threat or potential vulnerabilities in its applications via its bug bounty program.

Meanwhile, a CertiK spokesperson told CryptoSlate that the firm was not in touch with Telegram and that news of the vulnerability had come from the security community. It added that the mobile version of the messaging application was secure from this vulnerability because it “does not directly execute executable programs like desktops, which generally require signatures.”

CertiK further stated that its social media post about the vulnerability intended to raise awareness of the potential issue and remind users of best practices.

The post Telegram debunks reported vulnerability in desktop app, confirms mobile security appeared first on CryptoSlate.

Read the article at CryptoSlate

Read More

Shiba Inu coin price prediction: Should you brace for another 20% drop?

Shiba Inu coin price prediction: Should you brace for another 20% drop?

SHIB's RSI shows strong bearish momentum, showing that the memecoin can dip into over...
May, 02, 2024
by AMBCrypto
CZ’s Trial Proves it Pays to Cooperate

CZ’s Trial Proves it Pays to Cooperate

His four-month sentence was vindication for the Binance founder’s legal strategy.
May, 02, 2024
by CoinDesk
CryptoRankNewsTelegram deb...

Telegram debunks reported vulnerability in desktop app, confirms mobile security


Telegram debunks reported vulnerability in desktop app, confirms mobile security
Apr, 09, 2024
1 min read
by CryptoSlate
Telegram debunks reported vulnerability in desktop app, confirms mobile security

The crypto-friendly messaging application Telegram has debunked claims that a vulnerability on its platform exposed its users to attacks.

The alleged vulnerability

Blockchain security firm CertiK said on April 9 that Telegram’s desktop application has a potential high-risk Remote Code Execution (RCE) vulnerability. The firm stated:

“Possible RCE detected in Telegram’s media processing in the Telegram Desktop application. This issue exposes users to malicious attacks through specially crafted media files, such as images or videos.”

According to CertiK, this vulnerability could allow malicious actors to send RCE to users, potentially exposing them to attacks via specially crafted media files.

The security firm clarified that the vulnerability is confined to desktop apps, which can execute programs contained within files. Mobile applications remain unaffected, as they do not execute programs.

CertiK advised users to deactivate the auto-download feature on the desktop application for security purposes. Users can adjust their media download settings to manual downloads in the app’s settings.

Telegram’s response

In an April 9 post on X (formerly Twitter), Telegram stated that the trending videos were likely a hoax as there was no such vulnerability on its platform.

Nevertheless, the platform urged users to report any threat or potential vulnerabilities in its applications via its bug bounty program.

Meanwhile, a CertiK spokesperson told CryptoSlate that the firm was not in touch with Telegram and that news of the vulnerability had come from the security community. It added that the mobile version of the messaging application was secure from this vulnerability because it “does not directly execute executable programs like desktops, which generally require signatures.”

CertiK further stated that its social media post about the vulnerability intended to raise awareness of the potential issue and remind users of best practices.

The post Telegram debunks reported vulnerability in desktop app, confirms mobile security appeared first on CryptoSlate.

Read the article at CryptoSlate

Read More

Shiba Inu coin price prediction: Should you brace for another 20% drop?

Shiba Inu coin price prediction: Should you brace for another 20% drop?

SHIB's RSI shows strong bearish momentum, showing that the memecoin can dip into over...
May, 02, 2024
by AMBCrypto
CZ’s Trial Proves it Pays to Cooperate

CZ’s Trial Proves it Pays to Cooperate

His four-month sentence was vindication for the Binance founder’s legal strategy.
May, 02, 2024
by CoinDesk