It’s a mystery … alleged unpatched Telegram zero-day allows device takeover, but Telegram denies

3 Min Read

A critical Telegram flaw could allow zero-click remote code execution on devices, but Telegram denies it.

Researcher Michael DePlante (@izobashi) of TrendAI Zero Day disclosed a new Telegram vulnerability through Zero Day Initiative (ZDI).

- Advertisement -

The vulnerability, tracked as ZDI-CAN-30207 (CVSS score of 9.8) allows attackers to execute code on targeted devices without any user interaction. This vulnerability is especially dangerous because an attacker can exploit it simply by sending a malicious animated sticker, with no action required from the victim. The vulnerability lies in how Telegram automatically processes media to generate previews, allowing crafted files to trigger code execution.

The flaw poses a serious security risk, especially as no patch is currently available, raising concerns across the cybersecurity community.


What do you think? Post a comment.


It’s a mystery … alleged unpatched Telegram zero-day allows device takeover, but Telegram denies | Philly PI

The vulnerability affects Telegram on Android and Linux; if exploited, it allows attackers to take full control of a device.

- Advertisement -

EXPLORE MORE

Why Russia Issued an Arrest Warrant for a Gay British Agitator

Caolan Robertson is an British YouTube video maker, amateur writer, and a…

Canada MAID Program: Truth About the 16,000 Assisted Deaths

A striking narrative has taken center stage in global health and policy…

The Colorado River Is Drying Up and the West Is Running Out of Easy Choices

Flow in the Colorado River has shrunk by about 20% since 2000,…

Did Trump’s FDA pick just make a 180 on abortion pills?

President Donald Trump’s Food and Drug Administration (FDA) Commissioner nominee, Dr. Heidi…

Conflict Hits 6 Months: Iran Says Diplomacy Can Return But "Pressure Doesn't Work"

In what will likely prove to be a very limited and ultimately…

France and Japan Build a Stronger Air Power Bridge Between Europe and the Indo-Pacific

French Rafale F4 fighters trained with Japanese F-2A/B combat aircraft at Hyakuri…

At this time it is unclear if threat actors have already exploited it in attacks in the wild.

The Zero Day Initiative did not disclose technical details about the vulnerability to give the company time to address it by July 24, 2026.

The Italian National Cybersecurity Agency (ACN) reported that Telegram has denied the disclosed zero-click vulnerability, stating it does not exist. The company says all stickers are validated server-side before delivery, preventing malicious files from being used as an attack vector and making code execution via stickers technically impossible.

“Following direct discussions, Telegram Messenger has formally denied the existence of the previously reported zero-click vulnerability, stating that the flaw does not exist. The vendor claims that every sticker uploaded to the platform undergoes mandatory validation on its servers before being distributed to client applications.” reads an update published on the ACN’s advisory. “According to this official position, the centralized filtering process prevents corrupted stickers from being used as an attack vector, making it technically impossible to execute malicious code through this method.”

As a mitigation measure, Telegram Business users can limit incoming messages from new contacts. In Settings → Privacy and Security → Messages, they can restrict messages to saved contacts or Premium users only.

Exploits targeting popular platforms like Telegram can be worth millions on underground markets, and threat actors can quickly weaponize them.

Share This Article

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted