Back to directory
WRITEUP #5008

Telegram (v4.9.155353) was rendering file:// links + opening them via NSWorkspace.open -> code execution.

RCE
by@vladimir_metnew(Vladimir Metnew)
Bounty
500
Program
Telegram
Published
Dec 8, 2019
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://github.com/Metnew/telegram-links-nsworkspace-open
RELATED WRITEUPS
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
[2,500$ Bug Bounty Write-Up] Remote Code Execution (RCE) via unclaimed Node package
RCEDependency confusion
Attacking PowerShell CLIXML Deserialization
DeserializationInsecure deserialization
Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS
RCEArbitrary file write
We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI
RCETLD hacking

Built with ❤️ by Shubham Rawat