We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-7014

Improper multimedia file attachment validation in Telegram for Android app



AssignerESET
Reserved2024-07-23
Published2024-07-23
Updated2024-08-01

Description

EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.



HIGH: 7.1CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H

Product status

Default status
unaffected

Any version
affected

Timeline

2024-06-25:Reported to Telegram security team
2024-07-10:Telegram replied that the issue is fixed

Credits

Lukas Stefanko, ESET reporter

References

https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/

cve.org CVE-2024-7014

nvd.nist.gov CVE-2024-7014

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-7014
Subscribe to our newsletter to learn more about our work.