logo

Storm Brews Over Critical, No-Click Telegram Flaw

ID: 80fd48c3-64ff-56d0-ae4b-2f8003e5035d

STIX ID: report--80fd48c3-64ff-56d0-ae4b-2f8003e5035d

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Elizabeth Montalbano

...
...

ZDI disclosed a high-severity Telegram vulnerability (tracked as ZDI-CAN-30207) that allegedly enables zero-click remote code execution via corrupted animated stickers on Android and Linux clients; initial CVSS was 9.8 but ZDI lowered it to 7.0 after Telegram described server-side mitigations, while Telegram denies the vulnerability and full technical details remain embargoed until July 26.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.