logo

Telegram fixes Windows app zero-day used to launch Python scripts

ID: 221fc46d-f30a-5c6e-be7d-e04588b1cdb0

STIX ID: report--221fc46d-f30a-5c6e-be7d-e04588b1cdb0

Feed Name: Bleeping Computer

Threat Score
35/100

Date Published: 2024-04-12

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Telegram Desktop for Windows had a coding typo that omitted the .pyzw Python zipapp extension from its list of risky file types, allowing .pyzw files (when associated with Python on the system) to launch automatically when clicked—attackers could disguise such files as videos; a proof-of-concept was demonstrated, Telegram implemented a server-side mitigation and fixed the source mapping, and the impact was limited to a small fraction of users who had the relevant Python setup.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.