Web Hack List

Collected research

Telegram anonymity fails in desktop - CVE-2018-17780

Telegram anonymity fails in desktop

Telegram's desktop and Windows Phone clients forced peer-to-peer calls with no setting to refuse them, so placing or answering a call exposed both parties' public and private IP addresses to each other. Anyone able to ring a user could therefore locate them; fixed in tdesktop 1.3.17 and tracked as CVE-2018-17780.

Record

Document
Telegram anonymity fails in desktop
Researcher
Dhiraj Mishra
Published by
inputzero.io
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Dhiraj Mishra, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .