A vulnerability disclosure tracked as ZDI-CAN-30207 alleges that Telegram for Android and Linux contains a critical zero-click remote code execution flaw that could let an attacker take over a device by sending a specially crafted animated sticker. The reported issue, credited to researcher Michael DePlante of TrendAI Zero Day through the Zero Day Initiative, was described with a CVSS score of 9.8 and said to trigger during automatic sticker preview generation, requiring no user interaction.
Telegram has publicly denied that the vulnerability exists, saying stickers are validated server-side before delivery and that code execution through stickers is technically impossible. Italy’s National Cybersecurity Agency (ACN) published a notice about the alleged 0-click issue and later reflected Telegram’s denial, while technical details remain withheld and no patch has been released as the vendor is given time to address the claim by July 24, 2026; there is also no confirmation of exploitation in the wild.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Telegram formally denied that the reported vulnerability exists, stating that stickers are validated server-side before delivery and that code execution through stickers is technically impossible. Italy's National Cybersecurity Agency published an update reflecting Telegram's denial.
Researcher Michael DePlante of TrendAI Zero Day reported an alleged Telegram vulnerability through the Zero Day Initiative, describing it as a critical zero-click remote code execution flaw affecting Telegram on Android and Linux. The issue was said to allow device takeover via a malicious animated sticker processed during preview generation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.