With the Telegram’s “people in the vicinity” function, you can determine the exact location of those for whom the function is activated.
Bounty hunter and researcher Ahmed Hassan picked up the quirk and reported it to the messaging app’s security.
Hassan had noticed a similar problem with the Line app a few years ago and picked it up again with Telegram. However, when Telegram reported it, it said it was not a problem and there was no bug bounty for it.
Hassan fears the feature will basically allow anyone to find your exact location, which is incredibly dangerous. This is especially true of Telegram, which while a normal messaging app in itself, is preferred by extremist groups and hackers.
How ‘People Nearby’ works
In one blog entryHassan outlined how the feature’s distance model can be used to triangulate a user’s exact location.
If “people nearby” is activated in a user’s Telegram, you can see how far people are from your location. The list of people nearby shows how far they are from your location.
This allows one to “falsify” the exact position of the others by three points and use that to draw three triangulation circles according to Hassan.
While trying to forge a user’s address, Hassan found that this process enabled him to find the exact home address.
Source link : https://www.techradar.com/news/telegrams-location-function-opens-users-up-to-hackers/