Telegram Desktop App Found to Be Leaking IP Addresses When Initiating Calls, Company Fixes Bug

Advertisement
By Sumit Chakraborty | Updated: 1 October 2018 13:04 IST
Highlights
  • The app leaked both public and private IP addresses during voice calls
  • The users did not have an option to turn off the feature
  • The company has issued a fix for the issue in v1.3.17 beta and v1.4.0
Telegram Desktop App Found to Be Leaking IP Addresses When Initiating Calls, Company Fixes Bug

The researcher who found the Telegram bug was awarded EUR 2,000 (roughly Rs. 1,68,900)

Instant messaging app Telegram, known for its end-to-end encryption features, was found to contain a bug that would leak users' IP addresses. A security researcher discovered that the Telegram desktop app was leaking public and private IP addresses of users during voice calls. Additionally, users did not have an option to turn off the feature that could potentially leave them vulnerable to cyber-attacks. However, Telegram has reportedly fixed the bug in its latest updates. Notably, the company's security team has awarded the researcher EUR 2,000 (roughly Rs. 1,68,900) for reporting the bug in the app.

Security researcher Dhiraj Mishra reported the Telegram bug, which he says was causing the desktop app to be leaking both public and private IP addresses during voice calls to be made over a P2P (peer-to-peer) framework. While smartphone users have the option of turning off P2P calls by changing the settings to other options by going to Settings > Privacy and security > Calls > Peer-To-Peer, there was no such option available for Telegram users on the desktop.

Photo Credit: Dhiraj Mishra/ InputZero

The voice calling feature in Telegram works by establishing a direct P2P connection between the users, thereby exchanging data packets between the two directly. Such a connection is said to directly expose the IP addresses of the users. As mentioned, Telegram app users on mobile can choose to prevent their IP addresses from being revealed by changing the settings to Nobody. According to Mishra, this option was absent on Telegram's desktop client. This could result in all calls initiated from the desktop version potentially leaking the users' IP addresses.

Advertisement

Notably, the company has now fixed the issue in the 1.3.17 beta and 1.4 versions of Telegram by adding the Nobody option in its desktop client settings. The IP address leak has received the CVE-2018-17780 vulnerability identifier and as mentioned, the company has rewarded a bounty to Mishra for his bug report. Users can now go to Settings > Privacy and security > Calls > Peer-To-Peer and set the option to Nobody.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Telegram
Advertisement

Related Stories

Popular Mobile Brands
  1. Google I/O 2025: Here Are All the Major AI Announcements
  2. Oppo Reno 14 Series to Arrive With Integrated Google Gemini Features
  3. Android 16 Release: All You Can Expect from Google's Upcoming OS Update
  4. Infinix GT 30 Pro 5G With MediaTek Dimensity 8350 Ultimate SoC Launched
  5. Xiaomi 15s Pro Design, Camera Details Teased Ahead of Launch Today
  6. Honor 400 Series Confirmed to Get Six Years of Android Updates
  7. HP Launches OmniStudio X All-in-One PC With Intel Core Ultra 7 CPU
  1. Xiaomi 15s Pro Design, Camera Details Teased Ahead of Launch; Confirmed to Get Periscope Telephoto Camera
  2. Honor 400 Series to Get Six Years of Android Updates, AI Features Powered by Google’s Veo 2
  3. Samsung Galaxy Watch 8 Classic CAD Renders Tease New Squircle Design, Extra Button: Report
  4. Cyberpunk 2077 Sequel Will Feature a Second City in Addition to Night City, Says Series Creator
  5. Trump Memecoin Holders Set to Dine With US President, Tron Founder Justin Sun Confirms Attendance 
  6. Amazon Working on Large Foldable Device Similar to Huawei MateBook Fold Ultimate: Ming-Chi Kuo
  7. Infinix GT 30 Pro 5G With MediaTek Dimensity 8350 Ultimate SoC, 5,500mAh Battery Launched: Price, Features
  8. Google Announces SynthID Detector That Can Identify Gemini-Generated Content at Google I/O 2025
  9. Realme Buds Air 7 Pro Global Launch Set for May 27; Colours, Key Features Revealed
  10. iQOO Watch 5 With 1.43-Inch AMOLED Display and TWS Air 3 With Up to 45 Hours of Total Battery Life Launched
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.