Data Export Weakness in Telegram Desktop by Telegram
CVE-2020-25824
2.4LOW
Key Information:
- Vendor
Telegram
- Status
- Vendor
- CVE Published:
- 14 October 2020
What is CVE-2020-25824?
Telegram Desktop versions up to 2.4.3 have a vulnerability where the Export key within the Export Telegram Data wizard does not require passcode entry. This allows an attacker to exploit a scenario where an unsuspecting user opens the Export Wizard but becomes distracted. If the desktop is left unattended, an attacker can simply press the Export key, potentially gaining unrestricted access to all chat conversations and media files. This vulnerability highlights the importance of securing sensitive actions within software to prevent unauthorized data access.