‘High-risk’ Telegram vulnerability exposes users to attacks — CertiK
A major vulnerability on Telegram messenger is exposing users to malicious attacks, according to a new report released by the blockchain security firm CertiK.
CertiK Alert took to the social media platform X on April 9 to warn the public against a “high-risk vulnerability in the wild,” potentially allowing hackers to deploy a remote code execution (RCE) attack through Telegram’s media processing.
According to the post, CertiK’s team has discovered a “possible RCE” attack in Telegram’s media processing on Telegram Desktop application.
“This issue exposes users to malicious attacks through specially crafted media files, such as images or videos,” CertiK wrote.
To avoid the vulnerability, users should check their Telegram Desktop configuration and disable the auto-download feature. The feature can be disabled by going to “Settings” and then tapping on “Advanced.”
“Under the ‘Automatic Media Download’ section, disable auto-download for ‘Photos’, ‘Videos’, and ‘Files’ across all chat types (Private chats, groups, and channels),” CertiK noted.
Cointelegraph approached CertiK and Telegram for a comment regarding the new Telegram’s vulnerability but did not receive a response at the time of publication.
Telegram is a major cryptocurrency-friendly messenger that allows users to communicate and exchange files and transact cryptocurrencies like Bitcoin ( BTC ) and Toncoin (TON) using its custodial wallet solution called, simply, Wallet .
The “custodial” part means that Wallet doesn’t give users the private key by default but rather puts the assets in its own custody to help industry newcomers avoid self-custody responsibilities.
Related: Telegram channels eligible for 50% ad revenue, but there’s a catch
The newly discovered vulnerability on Telegram isn’t its first. In 2023, Google engineer Dan Reva found a significant bug that could allow attackers to activate the camera and microphone on laptops running macOS.
In 2021, a security researcher from Shielder discovered a similar media-related issue on Telegram, which reportedly allowed attackers to send modified animated stickers, which could have exposed the victims’ data.
Telegram has been actively addressing potential vulnerabilities on its app, though. Telegram’s bug bounty program has been active since 2014, offering developers and the security research community the opportunity to submit their reports and be eligible for bounties ranging from $100 to $100,000 or more, depending on the severity of the issue.
Magazine: 1 in 6 new Base meme coins are scams, 91% have vulnerabilities
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Aya Miyaguchi is the New President of the Ethereum Foundation
Hamster Kombat Launches First Gaming-Focused Layer-2 Blockchain on TON
Polkadot ETF Filing Submitted by Nasdaq to SEC
Phoenix Labs announces Dauntless shutdown following studio layoffs
Share link:In this post: Phoenix Labs has announced that Dauntless, its monster-hunter-like game, will shut down on May 29, 2025. Dauntless’ closure comes after the game studio repeatedly laid off staff after Forte, a crypto firm, acquired it. Phoenix Labs has yet to reveal the future of its other projects, such as Fae Farm.
Trending news
MoreCrypto prices
More








