Elektrine lite

← Feed

@LexYeen@plush.city

Post #818952

2026-03-27 23:07 UTC

TL;DR: Turn on auto-update so you get patched ASAP, and change your Privacy and Security settings so you can't just get messaged out of the blue by malicious actors or their bots. This was discovered literally yesterday, BTW, so :boost_ok: https://securityonline.info/telegram-critical-zero-click-vulnerability-zdi-can-30207/

Replies (9)

  • @mynameistillian@plush.city 2026-03-27 23:11

    @LexYeen holy fucking maria magdalena on a fucking pogo stick how many ads and popups are there

    Open ##1774684

  • @rey@toot.cat 2026-03-27 23:15

    @LexYeen the workaround of blocking random messages is a Premium-only feature, of course *gets another drink*

    Open ##1774686

  • @Phorm@dragon.style 2026-03-27 23:33

    @LexYeen Jesus Fuck So unless I'm misreading this: there is no patch currently available. Additionally, the option to block messages from unknown senders is behind a paywall. Meaning if you don't pay for Telegram right now, you are exposed no matter what.

    Open ##1774692

  • @gremlin@critter.cafe 2026-03-28 05:27

    @LexYeen is this some kind of Ragebait? Blocking Messages is a Premium only Feature and the Site you shared is riddled with ADs

    Open ##1774694

  • @tiredbun@akko.wtf 2026-03-28 09:44

    @LexYeen CC: @yura It seems that there are more details and more people are talking about it.

    Open ##1774696

  • @mkljczk@pl.fediverse.pl 2026-03-28 10:11

    @LexYeen we know literally nothing about the vulnerability, we don't even know which platform it affects. anyway i recommend using PWA for telegram as it's literally the perfect PWA and the vuln likely doesn't affect the webapp and even if so, the browser sandbox should keep you safe

    Open ##1774697

  • @mdione@en.osm.town 2026-03-28 10:18

    @LexYeen why the CW? Sounds like one of those things one would like to people to read without the extra effort :)

    Open ##1774698

  • @fugi@amazonawaws.com 2026-03-28 10:25

    @LexYeen @star ... if there was a way to change that setting without paying them.

    Open ##1774701

  • @LexYeen as far as i can tell, the website extrapolates from the CVSS score (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) of an unpublished advisory (ZDI-CAN-30207 listed on https://www.zerodayinitiative.com/advisories/upcoming/) and brings no new factual information if the vulnerability is substantiated and the CVSS score is accurate, which is likely, this is pretty bad, but there is very little information, it's not even clear whether this affects the Telegram app (or which ones) or server. Also, CVSS scores can be pretty misleading

    Open ##1774702