Spoofing attack in Telegram products - CVE-2020-12474
Published: May 5, 2020
Vulnerability identifier: #VU27540
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12474
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data passed via a public URL or a group chat invitation URL. A remote attacker can perform an IDN Homograph attack via Punycode.
Affected software
Telegram Desktop for Windows
Telegram for iOS
Telegram for Android
Telegram for iOS
Telegram for Android
How to mitigate CVE-2020-12474
Install updates from vendor's website.
Telegram Desktop for Windows - update to 2.1.0
Telegram for iOS - update to 6.1
Telegram for Android - update to 6.1.0_1938
Telegram for iOS - update to 6.1
Telegram for Android - update to 6.1.0_1938