Telegram Android EvilVideo <10.14.4 disguised video app
CVE-2024-7014 Published on July 23, 2024

Improper multimedia file attachment validation in Telegram for Android app
EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.

NVD

Timeline

Reported to Telegram security team

Telegram replied that the issue is fixed 15 days later.

Weakness Type

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.


Products Associated with CVE-2024-7014

Want to know whenever a new CVE is published for Telegram? stack.watch will email you.

 

Affected Versions

Telegram for Android:

Exploit Probability

EPSS
17.55%
Percentile
95.15%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.