International Business Weekly
  • Home
  • News
  • Politics
  • Business
  • National
  • Culture
  • Lifestyle
  • Sports
No Result
View All Result
  • Home
  • News
  • Politics
  • Business
  • National
  • Culture
  • Lifestyle
  • Sports
No Result
View All Result
International Business Weekly
No Result
View All Result
Home National

Telegram For Mac Malware Can Access Your Camera And Microphone; New Update Released

May 17, 2023
in National
0
Telegram For Mac Malware Can Access Your Camera And Microphone; New Update Released
0
SHARES
2
VIEWS
Share on FacebookShare on Twitter


AFP

KEY POINTS

  • The problem in Telegram messenger’s macOS app was discovered in February
  • The vulnerability made it possible for malware to access a device’s camera and microphone
  • Telegram said the desktop app that can be downloaded through its website does not have this issue

Telegram messenger has fixed a security issue that was detected in its macOS app available via the App Store.

The detected vulnerability made it possible for malware to access a device’s camera and microphone, Meduza reported.

Telegram said in a tweet Tuesday that it has already eliminated the weakness in a new update of the app it just submitted to Apple.

The desktop app that can be downloaded through Telegram’s website does not have this issue, the company said.

The problem was first revealed Monday in a blog post by software engineer Dan Revah.

“[U]sing a vulnerability of a third-party application can grant us additional permissions and allow us to bypass Apple’s privacy mechanism,” his report said.

Matt Johansen, who describes himself as a computer security veteran who has worked with startups and “the biggest financial companies in the world,” broke down the issue in a Twitter thread. He tweeted that the weakness in the Telegram macOS app was first discovered in February.

“The weakness involves macOS’s Transparency, Consent, and Control (TCC) mechanism. This mechanism manages access to ‘privacy-protected’ areas in macOS, which Telegram’s vulnerability can exploit,” Johansen said.

He said that macOS Root users can never access the microphone and screen recording unless the app has “direct user consent or manually granted permissions.”

However, the vulnerability in Telegram’s macOS app was able to “sidestep” this security measure, which, according to Johansen, comes down to “Entitlements and Hardened Runtime.”

Entitlements are the permissions given to a “binary” in order to access privileges in the device like access to the microphone and camera. On the other hand, Hardened Runtime is the one that prevents exploits.

“iOS requires an app to be signed with Hardened Runtime entitlement to be uploaded to the App Store. macOS doesn’t have this requirement. This loophole can potentially leave macOS apps more vulnerable,” Johansen said.

According to the timeline provided by Revah, the vulnerability was discovered on Feb. 2. He said that he contacted security@telegram.org about the issue, but Telegram’s security team reportedly did not address it.

On Feb. 10, the vulnerability was reported to MITRE, a government-funded research organization specializing in cybersecurity issues, and on Feb. 26, it was reported to VINCE to get assistance in coordination with Telegram to fix the issue and make it public.

On Monday, the grace period with VINCE ended, and the vulnerability was disclosed to the public.

A more secure desktop version of Telegram is now awaiting approval from Apple and is expected to be soon made available for download from the App Store.

A 3D printed Telegram logo is pictured on a keyboard in front of binary code in this illustration taken September 24, 2021.
Reuters / DADO RUVIC





Source link

Tags: accesscameraMacmalwareMicrophoneReleasedTelegramUpdate
Brand Post

Brand Post

I am an editor for IBW, focusing on business and entrepreneurship. I love uncovering emerging trends and crafting stories that inspire and inform readers about innovative ventures and industry insights.

Related Posts

Can Crowdsourcing AI fix UK Care?
National

Can Crowdsourcing AI fix UK Care?

February 14, 2026
Nothing opens 5,000 sq ft flagship store in Bengaluru; eyes deeper India push
National

Nothing opens 5,000 sq ft flagship store in Bengaluru; eyes deeper India push

February 14, 2026
Thousands of Homeland Security Employees, Including ICE and National Guard, to Work Without Pay
National

Thousands of Homeland Security Employees, Including ICE and National Guard, to Work Without Pay

February 13, 2026
Next Post
This is the Success Story of Steve Sidd – The No BS Consultant Who Puts it All on the Line

This is the Success Story of Steve Sidd – The No BS Consultant Who Puts it All on the Line

UBS Says Deal to Take Over Crisis-Hit Credit Suisse Leaves it With a Financial Hit of  Billion

UBS Says Deal to Take Over Crisis-Hit Credit Suisse Leaves it With a Financial Hit of $17 Billion

Navigatingthe Unchartered Waters of Inflation: How Financial Advisers Can Help YouProtect Your Finances and Retirement

Navigatingthe Unchartered Waters of Inflation: How Financial Advisers Can Help YouProtect Your Finances and Retirement

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

ABOUT US

International Business Weekly is an American entertainment magazine. We cover business News & feature exclusive interviews with many notable figures

Copyright © 2026 - International Business Weekly

  • About
  • Advertise
  • Careers
  • Contact
No Result
View All Result
  • Home
  • Politics
  • News
  • Business
  • Culture
  • National
  • Sports
  • Lifestyle
  • Travel

Copyright © 2024 - International Business Weekly

سایت کازینو,سایت کازینو انفجار,سایت انفجار هات بت,سایت حضرات ,بت خانه ,تاینی بت ,سیب بت ,ایس بت بدون فیلتر ,ماه بت ,دانلود اپلیکیشن دنس بت ,بازی انفجار دنس,ازا بت,ازا بت,اپلیکیشن هات بت,اپلیکیشن هات بت,عقاب بت,فیفا نود,شرط بندی سنگ کاغذ قیچی,bet90,bet90,سایت شرط بندی پاسور,بت لند,Bababet,Bababet,گلف بت,گلف بت,پوکر آنلاین,پاسور شرطی,پاسور شرطی,پاسور شرطی,پاسور شرطی,تهران بت,تهران بت,تهران بت,تخته نرد پولی,ناسا بت ,هزار بت,هزار بت,شهر بت,چهار برگ آنلاین,چهار برگ آنلاین,رد بت,رد بت,پنالتی بت,بازی انفجار حضرات,بازی انفجار حضرات,بازی انفجار حضرات,سبد ۷۲۴,بت 303,بت 303,شرط بندی پولی,بتکارت بدون فیلتر,بتکارت بدون فیلتر,بتکارت بدون فیلتر, بت تایم, سایت شرط بندی بدون نیاز به پول, یاس بت, بت خانه, Tatalbet, اپلیکیشن سیب بت, اپلیکیشن سیب بت, بت استار, پابلو بت, پیش بینی فوتبال, بت 45, سایت همسریابی پيوند, بت باز, بری بت, بازی انفجار رایگان, شير بت, رویال بت, بت فلاد, روما بت, پوکر ریور, تاس وگاس, بت ناب, بتکارت, سایت بت برو, سایت حضرات, سیب بت, پارس نود, ایس بت, سایت سیگاری بت, sigaribet, هات بت, سایت هات بت, سایت بت برو, بت برو, ماه بت, اوزابت | ozabet, تاینی بت | tinybet, بری بت | سایت بدون فیلتر بری بت, دنس بت بدون فیلتر, bet120 | سایت بت ۱۲۰, ace90bet | acebet90 | ac90bet, ثبت نام در سایت تک بت, سیب بت 90 بدون فیلتر, یاس بت | آدرس بدون فیلتر یاس بت, بازی انفجار دنس, بت خانه | سایت, بت تایم | bettime90, دانلود اپلیکیشن وان ایکس بت 1xbet بدون فیلتر و آدرس جدید, سایت همسریابی دائم و رایگان برای یافتن بهترین همسر و همدم, دانلود اپلیکیشن هات بت بدون فیلتر برای اندروید و لینک مستقیم, تتل بت - سایت شرط بندی بدون فیلتر, دانلود اپلیکیشن بت فوت - سایت شرط بندی فوت بت بدون فیلتر, سایت بت لند 90 و دانلود اپلیکیشن بت 90, سایت ناسا بت - nasabet, دانلود اپلیکیشن ABT90 - ثبت نام و ورود به سایت بدون فیلتر, https://planer4.com/, http://geduf.com/,, بازی انفجار, http://foreverliving-ar.com/, https://wediscusstech.com/, http://codesterlab.com/, https://www.9ja4u.com/, https://pimpurwhip.com/, http://nubti.com/, http://www.casinoherrald.com/, http://oigor.com/, http://coinjoin.art/, بازی مونتی