PT-2019-10741 · Telegram · Telegram Android
Published
2019-01-03
·
Updated
2023-02-04
·
CVE-2018-3986
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Telegram Android messaging application version 4.9.0
Description
An information disclosure issue exists in the "Secret Chats" functionality, which allows users to delete chat traces. However, a bug leaves behind photos taken and shared in secret chats, even after deletion. These photos remain stored on the device and are accessible to all installed Android applications.
Recommendations
For version 4.9.0, consider restricting access to the "Secret Chats" functionality until a fix is available, and manually review and delete any sensitive photos that may have been left behind.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telegram Android