First published: Tue Apr 20 2021(Updated: )
** DISPUTED ** The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied message (e.g., in the Persian language) into a channel or group. The crash occurs in MtProtoKitFramework. NOTE: the vendor's perspective is that "this behavior can't be considered a vulnerability."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Telegram Telegram | =7.6.2 | |
=7.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-30496.
The severity of CVE-2021-30496 is medium with a severity value of 5.7.
The version affected by CVE-2021-30496 is 7.6.2 for iOS.
A remote authenticated user can cause a denial of service (application crash) by pasting an attacker-supplied message (e.g., in the Persian language) into a channel or group using the Telegram app for iOS.
There are no known workarounds or fixes available for CVE-2021-30496. It is recommended to update to the latest version of the Telegram app for iOS when a fix becomes available.