According to Mishra’s discovery, the IP address leak problem exists in the Telegram Desktop clients, tdesktop and Telegram for Windows. As stated by the researcher,
“Strangely tdesktop 1.3.14 and Telegram for windows (3.3.0.0 WP8.1) leaks end user private and public IP address while making calls. “Telegram allows the users to make calls over P2P. While doing so, users can modify the settings to control their IP addresses leak by choosing “nobody” or “never” in the “Peer-to-Peer” settings.
These settings are available only in case of the mobile (Android and iOS) apps, and not in the desktop clients. Thus, users making calls via desktop apps inadvertently exposed their IP addresses.
While talking to Bleeping Computer, Mishra explained,
“If you see in my video PoC there are 3 IP's that leak: 1. Telegram server IP (That's Ok) 2. Your own IP (Even that's okay too) 3. End user IP (That's not okay)”
https://twitter.com/telegram/status/1046157720909484037
- telegram
The vulnerability discovered by Mishra received CVE number CVE-2018-17780, he was awarded a bounty of €2000.
Users can simply protect themselves from such accidental IP leaks via Telegram by making sure that their apps’ P2P setting is set to “My Contacts” or “Nobody”/”Never”. This can be done via the following settings menu.
Settings > Privacy and security > Calls > Peer-to-Peer