
Cloud Vulnerability DB
A community-led vulnerabilities database
Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS were discovered to be vulnerable to an IDN Homograph attack via Punycode in public URLs or group chat invitation URLs. The vulnerability was reported in April 2020 and was assigned CVE-2020-12474. The issue affected multiple versions of Telegram across different platforms (GitHub Report).
The vulnerability allows remote attackers to conduct spoofing attacks by exploiting an IDN Homograph attack flaw. The issue specifically involves the handling of Punycode-embedded URLs in the application, which could be used to create deceptive links that appear legitimate to users. When clicked, these URLs would open in the application's webview or default browser, potentially redirecting users to malicious websites (GitHub Report).
The vulnerability enables attackers to conduct spoofing attacks through specially-crafted content. Users could be deceived into visiting malicious websites through what appears to be legitimate shared link URLs or group chat invites, potentially exposing them to various forms of attacks or suspicious activities (GitHub Report).
Telegram addressed this vulnerability by releasing patches in version 6.1 for mobile platforms and version 2.1 for desktop applications. Users are advised to update their Telegram applications to these or later versions to protect against this vulnerability (GitHub Report).
The vulnerability was reported to Telegram in the first week of April 2020, and the vendor acknowledged it in the second week. The issue was subsequently patched, and the researcher received a four-digit bounty in the third week of April 2020 (GitHub Report).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."