The crypto-friendly messaging application Telegram has debunked claims that a vulnerability on its platform exposed its users to attacks.
The alleged vulnerability
Blockchain security firm CertiK said on April 9 that Telegram’s desktop application has a potential high-risk Remote Code Execution (RCE) vulnerability. The firm stated:
“Possible RCE detected in Telegram’s media processing in the Telegram Desktop application. This issue exposes users to malicious attacks through specially crafted media files, such as images or videos.”
According to CertiK, this vulnerability could allow malicious actors to send RCE to users, potentially exposing them to attacks via specially crafted media files.
The security firm clarified that the vulnerability is confined to desktop apps, which can execute programs contained within files. Mobile applications remain unaffected, as they do not execute programs.
CertiK advised users to deactivate the auto-download feature on the desktop application f
We współpracy z: https://cryptoslate.com/telegram-debunks-reported-vulnerability-in-desktop-app-confirms-mobile-security/