CVE-2021-27204
MEDIUMTelegram < 7.4.0 - Cleartext Storage of Sensitive Information
Title source: llmDescription
Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://www.inputzero.io/2020/12/telegram-privacy-fails-again.html
Exploit, Third Party Advisory x_refsource_misc
https://www.youtube.com/watch?v=zEt-_5b4OaA
Scores
CVSS v3
5.5
EPSS
0.0029
EPSS Percentile
20.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-312
Status
published
Products (1)
telegram/telegram
< 7.4.0
Published
Feb 12, 2021
Tracked Since
Feb 18, 2026