writeups.xyz writeups.xyz / Telegram

Title Vulnerabilities Programs Authors
Find out the IP address through a call to Telegram…
Chaining Telegram bugs to steal session-related files.
Telegram users' privacy has been violated again. Messenger representatives demand not to disclose details
Telegram bug in terminated sessions
Telegram Report: SSRF leads to DOS attack [Reports that didn't make it]
Allow arbitrary URLs, expect arbitrary code execution
Hunting for bugs in Telegram's animated stickers remote attack surface
The "P" in Telegram stands for Privacy
Exploiting popular macOS apps with a single “.terminal” file.
Telegram (v4.9.155353) was rendering file:// links + opening them via NSWorkspace.open -> code execution.
Telegram addresses another privacy issue
Official Telegram Web Client ClickJacking Vulnerability – When crypto is strong and client is weak
Telegram App Store Secret-Chat Messages in Plain-Text Database