Telegram Exposes Real Users IP Addresses, Bypassing Proxies on Android and iOS in 1-click
A vulnerability in Telegram's mobile clients allows attackers to reveal users' real IP addresses with minimal interaction. This flaw, known as a "one-click IP leak," enables an attacker to transform seemingly harmless username links into effective…
A vulnerability in Telegram's mobile clients allows attackers to reveal users' real IP addresses with minimal interaction. This flaw, known as a "one-click IP leak," enables an attacker to transform seemingly harmless username links into effective tracking tools.
The vulnerability is linked to Telegram's automatic proxy validation mechanism. When users click on a disguised proxy link, embedded behind a username, the app sends a request to the proxy server before integrating it. Notably, this request bypasses all user-configured proxies, directly exposing the user's real IP address.
Attackers create malicious proxy URLs, disguising them as clickable usernames. When a user clicks one, the following occurs:
Automatic proxy test : Telegram performs a connectivity probe to the attacker's server. Proxy bypass : The request ignores configured SOCKS5, MTProto, or VPN setups, using the device's native network stack. IP logging : The attacker's server logs the source IP, geolocation, and metadata.
A vulnerability in Telegram's mobile clients allows attackers to reveal users' real IP addresses with minimal interaction.
This issue affects both Android and iOS clients, posing a risk to millions of users who depend on Telegram for secure communications.
The vulnerability highlights the dangers of proxy-heavy applications amidst increasing state-sponsored tracking. Despite having over 950 million users, Telegram has not publicly addressed this issue. Similar vulnerabilities have affected other applications in the past.
Disable automatic proxy detection in settings, if possible. Refrain from clicking on unfamiliar usernames or links. Implement firewall rules to block outbound proxy requests (e.g., using Little Snitch on iOS or AFWall+ on Android). Stay informed about patches via Telegram's changelog.
Researchers stress the necessity for immediate corrective measures.
Based on reporting by Cyber Security News.
