Zero-dayMar 29, 2026
‼️ A security researcher at the Zero Day Initiative claims to have found a zero-day in Telegram (...
ZDI researcher claims critical CVSS 9.8 zero-day in Telegram via malicious sticker; Telegram denies flaw exists.
Summary
A security researcher at the Zero Day Initiative disclosed a claimed zero-day vulnerability (ZDI-CAN-30207) in Telegram with a critical CVSS 9.8 severity rating, allegedly exploitable through a corrupted sticker file. Telegram has publicly disputed the claim, stating the flaw does not exist. The disclosure highlights the tension between coordinated vulnerability reporting and vendor response verification.