Damus
Wolf480pl profile picture
Wolf480pl
@Wolf480pl
Looks like there's a bit more info on the zero-click Telegram RCE and holy shit this looks bad:

> This vulnerability allows an attacker to execute arbitrary code on a victim's device simply by sending a specially crafted animated sticker or media file. No user interaction is required

> A Telegram spokesperson denied the vulnerability's existence, claiming the research was incorrect.
https://github.com/gameworkerkim/Telegram-0-Click-RCE-SECURITY-VULNERABILITY-ANALYSIS-REPORT/blob/main/Telegram%200-Click%20RCE_ENG.md

#telegram #security
2
buherator · 6w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq0cq07ulfyc7y2l8rczk9s36g8j65tq3m6xk9us8hr3ua4ktfmaqq05h6ty This report looks pure AI slop, but nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqqxvmxpt0dsewmp6a8e8rac6tzyar0l0hp09smjem2y7wger5vklqevurxv does have a matching candidate liste...
⠠⠵ avuko · 5w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq0cq07ulfyc7y2l8rczk9s36g8j65tq3m6xk9us8hr3ua4ktfmaqq05h6ty From my translation: "The vendor states that each sticker loaded on the platform undergoes a mandatory validation procedure on its servers before being deployed to client application...