CVE-2024-7014 HIGH

CVE-2024-7014: Improper multimedia file attachment validation in Telegram for Android app

Vendor Android
Product Telegram for Android
Weakness CWE-20 · Input validation
Published July 23, 2024
Last update August 1, 2024

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H

What the vulnerability does

01Description

EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.

Key dates

02Disclosure timeline

July 23, 2024 CVE published
August 1, 2024 Record updated