First published: Tue Mar 14 2017(Updated: )
An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android. Secret chat messages are available in cleartext in process memory and a .db file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Telegram | =2.6 | |
Telegram | =1.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8688 is considered a high severity vulnerability due to the exposure of secret chat messages in plaintext.
CVE-2014-8688 allows attackers to access cleartext secret chat messages from the process memory and a database file.
CVE-2014-8688 affects Telegram Messenger version 2.6 for iOS and version 1.8.2 for Android.
To mitigate CVE-2014-8688, users should upgrade to the latest version of Telegram Messenger that addresses this vulnerability.
CVE-2014-8688 is categorized as an information disclosure vulnerability.