PT-2019-10741 · Telegram · Telegram Android

Published

2019-01-03

·

Updated

2023-02-04

·

CVE-2018-3986

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Telegram Android messaging application version 4.9.0
Description An information disclosure issue exists in the "Secret Chats" functionality, which allows users to delete chat traces. However, a bug leaves behind photos taken and shared in secret chats, even after deletion. These photos remain stored on the device and are accessible to all installed Android applications.
Recommendations For version 4.9.0, consider restricting access to the "Secret Chats" functionality until a fix is available, and manually review and delete any sensitive photos that may have been left behind.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2018-3986

Affected Products

Telegram Android