TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.
References
| Link | Resource |
|---|---|
| https://trueconf.com/blog/update/trueconf-8-5 | Product Release Notes |
| https://research.checkpoint.com/2026/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targets/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3502 | US Government Resource |
Configurations
History
No history.
Information
Published : 2026-03-30 19:16
Updated : 2026-06-17 10:43
NVD link : CVE-2026-3502
Mitre link : CVE-2026-3502
CVE.ORG link : CVE-2026-3502
JSON object : View
Products Affected
trueconf
- trueconf
CWE
CWE-494
Download of Code Without Integrity Check
