CVE-2021-41861
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Telegram application 7.5.0 through 7.8.0 for Android does not properly implement image self-destruction, a different vulnerability than CVE-2019-16248. After approximately two to four uses of the self-destruct feature, there is a misleading UI indication that an image was deleted (on both the sender and recipient sides). The images are still present in the /Storage/Emulated/0/Telegram/Telegram Image/ directory.
La aplicación Telegram versiones 7.5.0 hasta 7.8.0 para Android no implementa correctamente la autodestrucción de imágenes, una vulnerabilidad diferente a la de CVE-2019-16248. Después de aproximadamente dos a cuatro usos de la funcionalidad de autodestrucción, presenta una indicación de interfaz de usuario engañosa de que una imagen fue eliminada (tanto en el lado del remitente como del destinatario). Las imágenes siguen presentes en el directorio /Storage/Emulated/0/Telegram/Telegram Image/
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-10-01 CVE Reserved
- 2021-10-04 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://habr.com/ru/post/580582 | Third Party Advisory | |
https://pikabu.ru/story/konfidentsialnost_polzovateley_telegram_snova_narushena_predstaviteli_messendzhera_trebuyut_ne_raskryivat_podrobnostey_8511495 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://desktop.telegram.org/changelog#v-2-6-23-02-21 | 2021-10-08 | |
https://telegram.org/blog/autodelete-inv2/ru#avtomaticheskoe-udalenie-soobschenii | 2021-10-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Telegram Search vendor "Telegram" | Telegram Search vendor "Telegram" for product "Telegram" | >= 7.5.0 <= 7.8.0 Search vendor "Telegram" for product "Telegram" and version " >= 7.5.0 <= 7.8.0" | android |
Affected
|