Google engineer Dan Reva has discovered a vulnerability in the version of the Telegram messenger intended for macOS, which can allow attackers to use the laptop’s camera and microphone, the Gaming Deput website reports.
The vulnerability allows an attacker to inject a malicious dynamic library (Dylib) into the Telegram for macOS version. This will allow the hacker to record the video taken by the camera and store the recording in a hidden folder.
The website states that the reason for this vulnerability is that the Telegram messenger does not use Apple's built-in security mechanisms called Hardened Runtime and Entitlements.
It is also noted that this vulnerability exists partly because of Apple, as the company does not require Hardened Runtime for macOS applications, although it is required for iOS applications.
Dan Reva reported the existence of this problem to Telegram management back in February 2023, but has not yet received any response.
Remi Vaughn, a spokesperson at Telegram told NEWS.am Tech that this proposed weakness does not put users at risk by default.
“In order for the situation raised by the researcher to occur, a user must have malware installed on their system. This situation has more to do with Apple's permission security than it does with Telegram and can potentially affect any macOS app as a result. The real issue is that it seems to be possible to bypass Apple’s sandbox restrictions that were created specifically to prevent such abuse of third-party apps,” he added.
NEWS.am Tech reported earlier how fraudsters started using a new scheme to steal Telegram accounts by deceiving users. In particular, the user is asked to go through an authentication process in the bot, which is supposed to be able to find intimate photos of his friends and acquaintances. And when the user enters his information on the phishing website where he is invited to go, the fraudsters get full access to his account.






