CVE-2024-54916
MEDIUMTelegram Android APK <11.7.0 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-54916. PoCs published by SAHALLL.
AI-analyzed exploit summary The PoC demonstrates an authentication bypass in Telegram Android APK v11.7.0 by hooking the checkPasscode method in the SharedConfig class using Frida to always return true, bypassing passcode validation.
Description
An issue in the SharedConfig class of Telegram Android APK v.11.7.0 allows a physically proximate attacker to bypass authentication and escalate privileges by manipulating the return value of the checkPasscode method.
Exploits (1)
The PoC demonstrates an authentication bypass in Telegram Android APK v11.7.0 by hooking the checkPasscode method in the SharedConfig class using Frida to always return true, bypassing passcode validation.
References (2)
Scores
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H