CVE-2021-30496: Medium severity telegram vulnerability
DISPUTED The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied message (e.g., in the Persian language) into a channel or group. The crash occurs in MtProtoKitFramework. NOTE: the vendor's perspective is that "this behavior can't be considered a vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-30496.
What is the severity of CVE-2021-30496?
The severity of CVE-2021-30496 is medium with a severity value of 5.7.
Which version of the Telegram app is affected by CVE-2021-30496?
The version affected by CVE-2021-30496 is 7.6.2 for iOS.
How can a remote authenticated user exploit CVE-2021-30496?
A remote authenticated user can cause a denial of service (application crash) by pasting an attacker-supplied message (e.g., in the Persian language) into a channel or group using the Telegram app for iOS.
Are there any workarounds or fixes available for CVE-2021-30496?
There are no known workarounds or fixes available for CVE-2021-30496. It is recommended to update to the latest version of the Telegram app for iOS when a fix becomes available.