CVE-2023-26818: Medium severity Telegram Telegram macOS vulnerability
Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLDINSERTLIBRARIES flag.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
On affected systems, prevent or restrict use of the DYLD_INSERT_LIBRARIES environment variable (e.g., disallow user-controlled DYLD_INSERT_LIBRARIES via platform policy/launch environment) to mitigate file access and microphone/video recording abuse in Telegram 9.3.1 and 9.4.0.
Event History
Frequently Asked Questions
What is CVE-2023-26818?
CVE-2023-26818 is a vulnerability that allows attackers to access restricted files, microphone, or video recording in Telegram versions 9.3.1 and 9.4.0 on macOS using the DYLD_INSERT_LIBRARIES flag.
How severe is CVE-2023-26818?
CVE-2023-26818 has a severity rating of medium with a CVSS score of 5.5.
What software versions are affected by CVE-2023-26818?
Telegram versions 9.3.1 and 9.4.0 on macOS are affected by CVE-2023-26818.
How can attackers exploit CVE-2023-26818?
Attackers can exploit CVE-2023-26818 by using the DYLD_INSERT_LIBRARIES flag to gain access to restricted files, microphone, or video recording in Telegram.
Are there any fixes or patches available for CVE-2023-26818?
At the moment, there are no official fixes or patches available for CVE-2023-26818. It is recommended to update Telegram to the latest version once a patch is released.