Heap Buffer Overflow Vulnerability in Telegram Apps Across Multiple Platforms
CVE-2021-31322
5.5MEDIUM
What is CVE-2021-31322?
The Telegram application for Android, iOS, and macOS is susceptible to a heap buffer overflow due to a flaw in the LOTGradient::populate function of its customized rlottie library. This vulnerability enables a remote attacker to potentially manipulate heap memory out-of-bounds on users' devices through the use of specially crafted animated stickers. If exploited, it could lead to adverse effects on the application's functionality and security of the user's device.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
