QSearchQSearch

CVE-2021-41861

3.3 LOW

The Telegram application 7.5.0 through 7.8.0 for Android does not properly implement image self-destruction, a different vulnerability th...

Published: 2021-10-04 · Last updated: 2026-06-17

Severity and scoring

CVSS
3.3 LOW
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Affected products

VendorProduct
telegramtelegram

Description

The Telegram application 7.5.0 through 7.8.0 for Android does not properly implement image self-destruction, a different vulnerability than CVE-2019-16248. After approximately two to four uses of the self-destruct feature, there is a misleading UI indication that an image was deleted (on both the sender and recipient sides). The images are still present in the /Storage/Emulated/0/Telegram/Telegram Image/ directory.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2021-40532 Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension (9.8 CRITICAL)