PT-2018-13078 · Telegram · Org.Telegram.Messenger
Boonpoj Thongakaraniroj
+1
·
Published
2018-10-09
·
Updated
2024-08-05
·
CVE-2018-15542
CVSS v3.1
6.4
Medium
| Vector | AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
org.telegram.messenger application version 4.8.11
Description
The issue allows authentication bypass via runtime manipulation that forces a certain method's return value to
true, enabling an attacker to authenticate with an arbitrary passcode. The vendor notes that this is not considered an attack of interest within their threat model, specifically excluding Android devices on which rooting has occurred.Recommendations
For version 4.8.11, consider disabling the Passcode feature until a patch is available to prevent potential authentication bypass.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Org.Telegram.Messenger