Skip to main content
LiMP VPN
All news

Telegram Zero-Click Sticker Flaw Faces July 24 Disclosure

Telegram Zero-Click Sticker Flaw Faces July 24 Disclosure

In short: Trend Micro's Zero Day Initiative flagged a critical zero-click flaw in Telegram for Android and Telegram Desktop for Linux, tracked as ZDI-CAN-30207. A malicious animated sticker could reportedly run code on your device with no tap or confirmation. Telegram denies the flaw exists, but the coordinated disclosure deadline is 24 July 2026 — so if you use Telegram, update now and lock down your account.

What happened

Zero Day Initiative (ZDI), the vulnerability research arm of Trend Micro, publicly listed an unpatched flaw in Telegram under the identifier ZDI-CAN-30207. It was reported to Telegram on 26 March 2026, and — following ZDI's standard responsible-disclosure policy — the technical details are withheld until the vendor deadline of 24 July 2026. The case was covered by Security Affairs, Dark Reading and Germany's heise online, among others. With hundreds of millions of Telegram users in Russian-speaking regions, the story spread fast — and so did the panic.

What makes it serious is the class of bug: "zero-click." You don't have to open anything. Simply receiving a specially crafted message is enough to trigger it — the same category of flaw used against journalists and activists with commercial spyware. If it's real, an attacker could gain control of the device and reach your messages, contacts and active sessions. It's a sharp reminder of why protecting your messenger conversations is worth taking seriously.

How the sticker attack works

According to ZDI, the weakness lies in how Telegram automatically processes incoming media to build previews — in this case, animated stickers. A crafted sticker file could reportedly slip malformed data past that processing and trigger remote code execution without any user interaction. ZDI originally scored the issue 9.8 out of 10 (critical) on the CVSS scale, then on 30 March lowered it to 7.0 (high), citing server-side mitigations that Telegram described during the disclosure process.

Because there is no confirmed patch note and no CVE yet, the exact mechanics stay under embargo until the deadline. Russian security specialists cited in community discussions (including on Codeby) note that talk of a working file generator is circulating — which is exactly why the disclosure window is being watched so closely.

Telegram denies it — so what should you believe?

Telegram has categorically rejected the report. The company says every sticker uploaded to the platform is validated and scanned on its servers before it is ever delivered to client apps, so a corrupted sticker could not, in its view, be used as an attack vector. Italy's national cybersecurity agency (ACN) relayed that denial in its own advisory.

The honest answer for an ordinary user: without published technical details, neither side can be independently verified right now. But you don't need to resolve the dispute to protect yourself. Security hygiene that blunts a zero-click messenger bug is the same hygiene that protects you from dozens of other threats — so the sensible move is to act as if the risk is real until the 24 July disclosure clears it up.

What this means for you and how to stay safe

Update Telegram immediately. Install the latest version from the official App Store or Google Play. If a fix ships around the disclosure date, updating is what closes the door — an outdated app stays exposed even after everyone else is patched.

Reduce your exposure surface. In Telegram's privacy settings, restrict who can send you messages and media, and keep two-step verification switched on. More broadly, it helps to reduce tracking and spyware exposure on your phone and to review which apps hold sensitive permissions.

Protect the network layer. A VPN does not patch an app bug — only the update does that. But it protects a different layer: your traffic. On open or shared Wi-Fi it routes your connection through an encrypted tunnel and hides your real IP address, so no one on the same network can intercept the sessions and credentials an attacker would otherwise try to harvest. Use it together with prompt updates, two-factor authentication and a password manager. LiMP VPN is a no-logs service for iOS and Android — see the features and plans, and more privacy news on our blog.

Sources

This report is based on coverage by Security Affairs, Dark Reading, heise online and the Russian-language security community Codeby, plus the ZDI advisory ZDI-CAN-30207 (disclosure deadline 24 July 2026).

Telegram Zero-Click Sticker Flaw Faces July 24 Disclosure