** DISPUTED ** The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied message (e.g., in the Persian language) into a channel or group. The crash occurs in MtProtoKitFramework. NOTE: the vendor's perspective is that "this behavior can't be considered a vulnerability."
References
Link | Resource |
---|---|
https://t.me/joinchat/bJ9cnUosVh03ZTI0 | Vendor Advisory |
https://gist.github.com/raminfp/bf64c2974ee6949787329749148a4b31 | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-04-20 09:15
Updated : 2023-02-02 11:51
NVD link : CVE-2021-30496
Mitre link : CVE-2021-30496
JSON object : View
CWE
Products Affected
telegram
- telegram