Vulnerability in Telegram's Secret Chat Feature Affects Multiple Products
CVE-2018-20436
What is CVE-2018-20436?
The secret chat functionality in Telegram versions such as 4.9.1 for Android exhibits a significant security issue where Telegram servers make GET requests to URLs entered while composing messages. This behavior can inadvertently lead to sensitive data exposure if certain settings are misconfigured. It resembles a Server-Side Request Forgery (SSRF) issue, which allows attackers to exploit the behavior of the application by manipulating input URLs. This flaw could also extend to other products within the Telegram ecosystem, raising concerns over user privacy and data protection.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
