peter-iakovlev / Telegram

Telegram Messenger for iOS
3.21k stars 855 forks source link

[Security issue] iOS Telegram X: possibility to send unauthorized messages with Telegram Passcode set #231

Open kirinson321 opened 6 years ago

kirinson321 commented 6 years ago

There is a possibility to send any message to any contact, even though a Telegram Passcode is set and the app is locked. Steps to reproduce:

  1. Set a Telegram Passcode
  2. Lock the app
  3. Find any shareable media (e.g. a website, a photo from gallery)
  4. After clicking the "share" button, select Telegram X as an application to share through
  5. No popup/screen asking for passcode appears, you can send any message through a comment to any of your contacts now

Found on iOS 9.3.5, Telegram X version 5.0.2