The detection of critical vulnerability in Telegram for Android version 11.7.4 was reported by an independent researcher of 0x6rss. This vulnerability allows attackers to load malicious apk files to the victim’s device through a video built in Telegram to watch a video. The human rights project “First Department” paid attention to this.
The malicious program for the use of this vulnerability of the messenger has been sold on Darknet forums since mid -January and can already be used for espionage and extortion.
The attack may look something like this: the attacker sends the victim of the HTM file, which Telegram mistakenly recognizes as a video. However, the built -in video player does not reproduce him, and the user, following the advice of Telegram himself, opens it through the browser. As a result, a malicious program is triggered, and the attacker sets on a smartphone a person who has undergone an attack, spy or other malicious programs.
"First Department" gives recommendations on how to protect yourself from such attacks:
Telegram spoke about other vulnerabilities of Telegram and ways to reduce the risks of The Insider in the material “And Telegram is silent about the main thing. What vulnerabilities of the messenger should be remembered by Russian users. ”