SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-15514

The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attackers can find these numbers via the Group Info feature, e.g., by adding a significant fraction…

MEDIUM 5.3EPSS 2.26%

Does this matter?

Lower severity and a low EPSS score (2.26%). Track it; it rarely justifies an emergency change on its own.

Description

The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attackers can find these numbers via the Group Info feature, e.g., by adding a significant fraction of a region's assigned phone numbers.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
2.26% probability · 82th percentile
CISA KEV
Not listed
Affected
telegram/telegram
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.