CVE-2018-17613: Telegram Desktop

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKS5 protocol.

Affected products

  • Telegram Telegram Desktop: version 1.3.16 only

Published 2018-09-28. Last modified 2026-06-17.