According to information from the Anti-Fraud organization, there is a serious vulnerability in the Telegram messaging application that can affect users of Windows operating system computers.
The vulnerability stems from a typo by a programmer when coding the zipapp python extension. Specifically, instead of typing “pyzw,” the typo causes the command to change to “pywz.” This can lead to hackers executing the attack exploit code without any notification from the victim’s computer.
Sharing with VietNamNet , a representative of the Anti-Fraud organization said that although the typing error is small, its impact is large because it allows hackers to carry out attacks to take control of Windows computers.
Accordingly, hackers can hide executable files under any type of file, be it photos or videos sent to users via messages on Telegram. On some versions of Telegram Windows, downloading these files can be done automatically. Users are therefore completely passive against attacks if targeted by hackers.
“ Recently, there have been several warnings about this Telegram vulnerability on Russian hacker forums. This is a Zero-day vulnerability (a vulnerability that has never been known before). It can be used in many different ways. There has even been exploit code shared on private groups. Therefore, this vulnerability is very dangerous. ”, shared a representative of the Anti-Fraud organization.
Experts from the Anti-Fraud organization recommend that, to ensure safety, Telegram users, especially on Windows computers, should proactively turn off the automatic video and photo download feature and not click to download random photo or video files from strangers, or on public groups and channels.
To do this, users need to go to the “Settings” section of the Telegram application, find the “Data and storage” section, then turn off the automatic download feature for “Photos”, “Videos” and “Files” in the “Automatic media download” section.
Telegram has just released an update to fix the critical vulnerability. Telegram users should download this update immediately to protect themselves from attacks exploiting the vulnerability.
Source
Comment (0)