Telegram versions 9.3.1 and 9.4.0 for macOS are vulnerable to a privilege escalation attack where an attacker can leverage the DYLD_INSERT_LIBRARIES environment variable to inject malicious libraries into the Telegram process. This allows unauthorized access to restricted files, as well as the ability to activate the microphone or video recording features without user consent.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a weaponized exploit for CVE-2023-26818, a macOS TCC (Transparency, Consent, and Control) bypass vulnerability. The exploit is implemented as a set of Objective-C dynamic libraries and supporting code, targeting unauthorized access to the camera, microphone, and location services on macOS. The structure includes separate modules for camera (Cam-Exploit), microphone (Mic-Exploit), and location (Location-Exploit), each with test and exploit files. The 'libs' directory contains core exploit logic for each capability, which can be customized and compiled using the provided 'main.cpp' utility. The exploit records video, audio, or location data and exfiltrates it via HTTP POST requests to a configurable domain (defaulting to 'http://a.com'). The main.cpp file provides an interactive interface to configure the payload (recording duration, output filename, and exfiltration domain) and compile the appropriate dynamic libraries. The exploit is operational and can be easily customized for different exfiltration endpoints, making it highly weaponizable. The README provides compilation instructions and references to further vulnerability analysis.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.