Telegram = Pandora box ๐
9.8 on the CVSS scale, Critical
This CVE is with a very high score and itโs recent. Propagates via Telegram because of the specific improper file parsing. This leads to RCE exploit. No patch available! Anyone can be hacked.
Simply restrict your asset and use different communicators.

#cybersecurity #infosec #rce #zeroclick #vulnerability #telegram | Dmitriy Galasli | 10 comments
๐ง๐ต๐ถ๐ ๐ฐ๐ผ๐๐น๐ฑ ๐ฏ๐ฒ ๐๐๐ฒ๐ฑ ๐๐ผ ๐ต๐ฎ๐ฐ๐ธ ๐ฎ๐ป๐๐ผ๐ป๐ฒ A critical vulnerability has been discovered in Telegram, rated 9.8 on the CVSS scale. Details are not yet disclosed, but given the near-maximum score, it could potentially be a 0-click RCE โ meaning an attacker might gain access to a target device simply by sending a crafted payload through the client. The issue was discovered by Michael DePlante , a researcher known for hunting bugs in major companies such as Apple, Adobe, and Avast. In 2024 alone, he identified 37 vulnerabilities, bringing his total to over 150. Many of his findings involve improper file parsing, which increases the likelihood of RCE in platforms like Telegram. There is currently no patch available, and full disclosure is expected no later than 24 July 2026, once responsible disclosure timelines are met. ๐๐ผ๐ฟ ๐ป๐ผ๐ โ ๐ฒ๐๐ฒ๐ฟ๐๐ผ๐ป๐ฒ ๐บ๐ฎ๐ ๐ฏ๐ฒ ๐ฎ๐ณ๐ณ๐ฒ๐ฐ๐๐ฒ๐ฑ Research: https://lnkd.in/e8zrCNZ5 #CyberSecurity #InfoSec #RCE #ZeroClick #Vulnerability #Telegram | 10 comments on LinkedIn