CVE Vulnerabilities

CVE-2019-16248

Published: Sep 11, 2019 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The delete for feature in Telegram before 5.11 on Android does not delete shared media files from the Telegram Images directory. In other words, there is a potentially misleading UI indication that a sender can remove a recipients copy of a previously sent image (analogous to supported functionality in which a sender can remove a recipients copy of a previously sent message).

Affected Software

NameVendorStart VersionEnd Version
TelegramTelegram*5.11.0 (excluding)

References