PT-2018-13078 · Telegram · Org.Telegram.Messenger

Boonpoj Thongakaraniroj

+1

·

Published

2018-10-09

·

Updated

2024-08-05

·

CVE-2018-15542

CVSS v3.1

6.4

Medium

VectorAV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions org.telegram.messenger application version 4.8.11
Description The issue allows authentication bypass via runtime manipulation that forces a certain method's return value to true, enabling an attacker to authenticate with an arbitrary passcode. The vendor notes that this is not considered an attack of interest within their threat model, specifically excluding Android devices on which rooting has occurred.
Recommendations For version 4.8.11, consider disabling the Passcode feature until a patch is available to prevent potential authentication bypass.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2018-15542

Affected Products

Org.Telegram.Messenger