CVE-2020-12474: Medium severity telegram vulnerability
Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public URL or a group chat invitation URL.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Telegram vulnerability?
The vulnerability ID for this Telegram vulnerability is CVE-2020-12474.
Which software versions are affected by CVE-2020-12474?
Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS are affected by CVE-2020-12474.
What is the severity level of CVE-2020-12474?
The severity level of CVE-2020-12474 is medium.
How can an IDN Homograph attack be carried out in Telegram?
An IDN Homograph attack can be carried out in Telegram by using Punycode in a public URL or a group chat invitation URL.
Is there a fix available for CVE-2020-12474?
It is recommended to update Telegram Desktop to version 2.0.2 or newer, Telegram for Android to version 6.0.2 or newer, and Telegram for iOS to version 6.0.2 or newer to fix CVE-2020-12474.