Back to Feed
Zero-dayMar 29, 2026

‼️ A security researcher at the Zero Day Initiative claims to have found a zero-day in Telegram (...

ZDI researcher claims critical CVSS 9.8 zero-day in Telegram via malicious sticker; Telegram denies flaw exists.

Summary

A security researcher at the Zero Day Initiative disclosed a claimed zero-day vulnerability (ZDI-CAN-30207) in Telegram with a critical CVSS 9.8 severity rating, allegedly exploitable through a corrupted sticker file. Telegram has publicly disputed the claim, stating the flaw does not exist. The disclosure highlights the tension between coordinated vulnerability reporting and vendor response verification.