Headline
CVE-2021-27351
The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and UNIX, fails to invalidate a recently active session.
Hi World,
Please refer minimal poc for my discovered CVE-2021-27351 in Telegram Android 7.2.1 & earlier - Telegram Desktop (Unix, Windows) 2.4.7 & earlier
[ Description]
Telegram CVE-2021-27351 Insecure session termination
The Terminate Session feature in the Telegram application through 7.2.1 for Android, and
through 2.4.7 for Windows and UNIX, failed to invalidate a recently active session.
------------------------------------------
[VulnerabilityType Other]
Insecure session termination
------------------------------------------
[Vendor of Product]
Telegram
------------------------------------------
[Affected Product Code Base]
Telegram Android 7.2.1 & earlier - Telegram Desktop (Unix, Windows) 2.4.7 & earlier
------------------------------------------
Connect with me for more details on attack vector at Vijay Tikudave