Stack Based Overflow in Telegram App on Android, iOS, and macOS
CVE-2021-31315

5.5MEDIUM

Key Information:

Vendor

Telegram

Status
Vendor
CVE Published:
18 May 2021

What is CVE-2021-31315?

Telegram apps on Android, iOS, and macOS are susceptible to a stack-based overflow vulnerability in the blit function of the custom rlottie library. This security flaw could allow a remote attacker to manipulate Telegram's stack memory through specially crafted malicious animated stickers, leading to potential unauthorized access or exploitation of sensitive information on the affected devices.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.