telegram

2 articles
sort: new top best
clear filter
0 6/10

A clickjacking vulnerability in Telegram's web client allowed attackers to iframe the application using sandboxed iframes to bypass frame-busting JavaScript, combined with blocking the app.css stylesheet to circumvent CSS-based visibility controls, enabling CSRF attacks and unauthorized account actions. The vulnerability was fixed by implementing server-side X-Frame-Options headers.

Telegram Mohamed A. Baset Pavel Durov Seekurity
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details
0 7/10

Stored blind XSS vulnerability in Telegram iOS app allowing arbitrary HTML/JavaScript execution via unvalidated HTML files in webview, enabling device fingerprinting, user activity tracking, and IP geolocation. Successfully exploited by uploading malicious HTML file that executed JavaScript to extract navigator object data and communicate with attacker server.

Telegram WhatsApp Facebook CVE-2018-UNKNOWN omespino iPhone 6 iPhone 7 iOS 11.2.5 iOS 11.2.6 Telegram iOS 4.7.1
omespino.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details