Blog | G5 Cyber Security

A flaw in Slack could allow hackers to steal, manipulate downloaded files

Security researcher David Wells from Tenable discovered a critical flaw in version 3.3.7 of the Slack desktop app that could be exploited to steal and manipulate a targeted users downloaded files. The issue is classified as a download hijacking vulnerability that can be triggered by tricking a user into clicking on a specially crafted link pasted into a Slack channel. Slack awarded $500 the researcher under its bug bounty program under its $500 bounty program. The flaw has been classified as medium severity because it required user interaction.”]

Source: https://securityaffairs.co/wordpress/85725/hacking/slack-flaw-2.html

Exit mobile version