Vulnerability · NVD
CVE-2019-10044
HIGH 8.8
Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters exist in the same domain name, and the available font has an identical representation of characters from different alphabets.
Attack vector : Network
No privileges required
Show raw CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
3.28%
above median
percentile 87.3%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (2)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| telegram |
telegram All platforms (wildcard)
|
All platforms (wildcard) | — | cpe:2.3:a:telegram:telegram:*:*:*:*:*:*:*:* |
| telegram |
telegram All platforms (wildcard)
|
All platforms (wildcard) | — | cpe:2.3:a:telegram:telegram:*:*:*:*:*:*:*:* |