CVE-2021-41861
low-risk
Published 2021-10-04
The Telegram application 7.5.0 through 7.8.0 for Android does not properly implement image self-destruction, a different vulnerability than CVE-2019-16248. After approximately two to four uses of the self-destruct feature, there is a misleading UI indication that an image was deleted (on both the sender and recipient sides). The images are still present in the /Storage/Emulated/0/Telegram/Telegram Image/ directory.
Do I need to act?
-
0.06% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
3
CVSS 3.3/10
Low
LOCAL
/ LOW complexity
Affected Products (1)
Affected Vendors
References (8)
Release Notes
https://desktop.telegram.org/changelog#v-2-6-23-02-21
Third Party Advisory
https://habr.com/ru/post/580582/
Third Party Advisory
https://pikabu.ru/story/konfidentsialnost_polzovateley_telegram_snova_narushena_...
Release Notes
https://desktop.telegram.org/changelog#v-2-6-23-02-21
Third Party Advisory
https://habr.com/ru/post/580582/
Third Party Advisory
https://pikabu.ru/story/konfidentsialnost_polzovateley_telegram_snova_narushena_...
18
/ 100
low-risk
Severity
13/34 · Low
Exploitability
0/34 · Minimal
Exposure
5/34 · Minimal