PT-2025-50089 · Yandex+1 · Yandex Messenger+1

Published

2025-07-22

·

Updated

2025-12-14

·

CVE-2025-5469

CVSS v4.0

7.3

High

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Telemost versions prior to 2.245
Description An uncontrolled search path element issue exists in Yandex Messenger on MacOS, enabling search order hijacking. This affects Telemost.
Recommendations Update Telemost to version 2.245 or later.

Fix

Untrusted Search Path

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2025-08832
CVE-2025-5469

Affected Products

Telemost
Yandex Messenger