logo

It’s a mystery … alleged unpatched Telegram zero-day allows device takeover, but Telegram denies

ID: b57cca9b-71c1-59e3-937e-8d16a96fe58e

STIX ID: report--b57cca9b-71c1-59e3-937e-8d16a96fe58e

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A zero-day vulnerability (ZDI-CAN-30207, CVSS 9.8) disclosed by TrendAI/Zero Day Initiative was reported to allow zero-click remote code execution on Android and Linux Telegram clients via malicious animated stickers, potentially enabling full device takeover; ZDI withheld technical details to allow a fix. Telegram has denied the vulnerability, stating stickers are validated server-side and claiming code execution via stickers is technically impossible; the advisory notes no confirmed in-the-wild exploitation and suggests privacy settings mitigations for Business users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.