{"id":75545,"date":"2024-04-09T10:22:01","date_gmt":"2024-04-09T14:22:01","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=75545"},"modified":"2024-04-09T10:22:04","modified_gmt":"2024-04-09T14:22:04","slug":"certik-warns-users-against-high-risk-telegram-vulnerability","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/certik-warns-users-against-high-risk-telegram-vulnerability\/","title":{"rendered":"CertiK Warns Users Against \u2018High-risk\u2019 Telegram Vulnerability"},"content":{"rendered":"\n<p>In fresh research, the blockchain security company CertiK claims that <a href=\"https:\/\/coinscreed.com\/staging\/wallet-crypto-trading-bot-debuts-on-telegram-messenger.html\" target=\"_blank\" rel=\"noreferrer noopener\">Telegram Messenger<\/a> users are vulnerable to malicious attacks due to a significant vulnerability.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"563\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-103-1024x563.png\" alt=\"CertiK Warns Users Against \u2018High-risk\u2019 Telegram Vulnerability  \" class=\"wp-image-65479\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-103-1024x563.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-103-300x165.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-103-768x422.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-103-18x10.png 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-103-750x412.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-103.png 1053w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">CertiK Warns Users Against \u2018High-risk\u2019 Telegram Vulnerability  <\/figcaption><\/figure>\n\n\n\n<p>On April 9, CertiK Alert used the social media platform X to alert users to a &#8220;high-risk vulnerability in the wild&#8221; that might enable hackers to use Telegram's media processing to launch a remote code execution (RCE) attack.<\/p>\n\n\n\n<p>The post claims that a &#8220;possible RCE&#8221; exploit in Telegram's media processing in the Telegram Desktop application has been found by CertiK's team.<\/p>\n\n\n\n<p>&#8220;This vulnerability puts users at risk of malicious attacks via carefully crafted media files, like pictures or videos,&#8221; stated CertiK.<\/p>\n\n\n\n<p>Users should verify their Telegram Desktop configuration and turn off the auto-download option to prevent the vulnerability. You can turn off the feature by selecting &#8220;Advanced&#8221; from the &#8220;Settings&#8221; menu.<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"763\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-48-750x763.png\" alt=\"Source: CertiK\" class=\"wp-image-75561\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-48-750x763.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-48-295x300.png 295w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-48-768x782.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-48-75x75.png 75w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-48.png 795w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\">Source:\u00a0<a href=\"https:\/\/x.com\/CertiKAlert\/status\/1777633778359267736\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CertiK<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/figcaption><\/figure>\n\n\n\n<p>&#8220;Disable auto-download for photos, videos, and files across all chat types (private chats, groups, and channels) under the &#8216;Automatic Media Download' section,&#8221; said CertiK.<\/p>\n\n\n\n<p>At the time of publication, Cointelegraph had not heard back from CertiK or Telegram regarding the new vulnerability in Telegram.<\/p>\n\n\n\n<p>With its custodial wallet solution, Wallet, users may transact cryptocurrencies like <a href=\"https:\/\/coinscreed.com\/staging\/toncoin-flips-chainlink-can-it-sustain-the-momentum.html\" target=\"_blank\" rel=\"noreferrer noopener\">Bitcoin and Toncoin<\/a> (TON) and communicate with each other using Telegram, a popular chat that supports cryptocurrencies.<\/p>\n\n\n\n<p>&#8220;Custodial&#8221; refers to Wallet placing the assets in its own custody rather than providing users with the private key by default to shield novices in the market from assuming self-custody obligations.<\/p>\n\n\n\n<p>Telegram has had vulnerabilities before, this being only the most recent one. A Google engineer, Dan Reva discovered a severe flaw in 2023 that would let intruders turn on the microphone and camera on macOS laptops.<\/p>\n\n\n\n<figure class=\"wp-block-image size-jnews-featured-750\"><img decoding=\"async\" width=\"750\" height=\"505\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-49-750x505.png\" alt=\"\" class=\"wp-image-75562\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-49-750x505.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-49-300x202.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-49-768x517.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2024\/04\/image-49.png 944w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><figcaption class=\"wp-element-caption\">Source:\u00a0<a href=\"https:\/\/x.com\/danrevah\/status\/1658050807026143235\" target=\"_blank\" rel=\"noreferrer noopener\">Dan Rehah<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/figcaption><\/figure>\n\n\n\n<p>A security researcher from Shielder found a similar media-related problem on Telegram in 2021. This bug allowed attackers to send animated stickers that were altered, potentially exposing the victims' data.<\/p>\n\n\n\n<p>However, Telegram has been aggressively patching any holes in its program. Since its launch in 2014, Telegram's<a href=\"https:\/\/coinscreed.com\/staging\/terra-luna-classic-propose-bug-bounty-program.html\" target=\"_blank\" rel=\"noreferrer noopener\"> bug bounty program<\/a> has allowed developers and security researchers to submit reports and potentially earn prizes of up to $100,000, depending on the severity of the issue.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In fresh research, the blockchain security company CertiK claims that Telegram Messenger users are vulnerable to malicious attacks due to a significant vulnerability. On April 9, CertiK Alert used the social media platform X to alert users to a &#8220;high-risk vulnerability in the wild&#8221; that might enable hackers to use Telegram&#8217;s media processing to launch [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":65479,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[6357,5817,6700,11865],"class_list":["post-75545","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-certik","tag-hack-2","tag-vulnerability","tag-telegram-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/11\/image-103.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/75545","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=75545"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/75545\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/65479"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=75545"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=75545"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=75545"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}