Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because of an unsafe default behavior in which P2P connections are accepted from clients outside of the My Contacts list.
2018-09-29T19:29:00.237
2024-11-21T03:54:57.610
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | telegram | telegram_desktop | 1.3.14 | Yes |
| Application | telegram | telegram_messenger | 3.3.0.0 | Yes |