Heap Buffer Overflow Vulnerability in Telegram Apps Across Multiple Platforms
CVE-2021-31322

5.5MEDIUM

Key Information:

Vendor

Telegram

Status
Vendor
CVE Published:
18 May 2021

What is CVE-2021-31322?

The Telegram application for Android, iOS, and macOS is susceptible to a heap buffer overflow due to a flaw in the LOTGradient::populate function of its customized rlottie library. This vulnerability enables a remote attacker to potentially manipulate heap memory out-of-bounds on users' devices through the use of specially crafted animated stickers. If exploited, it could lead to adverse effects on the application's functionality and security of the user's device.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.