Telegram Vulnerability Alert: CertiK Unveils Security Risk Details

4 Min Read Tags:

HIGHLIGHTS

  • CertiK has identified a high-risk vulnerability in the Telegram messaging app that allows hackers to infect devices with malware using media files.
  • Experts recommend disabling the Auto-download feature for media files in Telegram to mitigate risk.
  • Community reactions are mixed, with some pointing out that the vulnerability has been known for some time.
  • CertiK previously faced skepticism from the Web3 community over its findings related to Solana Saga’s security.

Introduction to the Telegram Vulnerability

Security firm CertiK has announced the discovery of a high-risk vulnerability within the popular messaging app, Telegram. This vulnerability allows attackers to execute remote code (RCE) through media files that are automatically downloaded by the app, potentially infecting the user’s device with malware.

Understanding the Threat

According to CertiK, hackers disguise malware as ordinary videos or images, which can then be automatically downloaded and executed by Telegram, compromising the device without any user interaction. This exploit poses a significant threat to the privacy and security of Telegram users, potentially granting attackers access to personal information, login credentials, and more.

User Protection Measures

In light of these findings, CertiK experts strongly advise Telegram users to disable the auto-download feature for media files. This precautionary measure can significantly reduce the risk of inadvertently downloading malicious content. Users can adjust these settings within the Telegram app to manually select which media files to download.

Community Skepticism and Previous Incidents

The revelation has received a mixed response from the community, particularly on platform X (formerly Twitter). Some users have criticized CertiK’s announcement, pointing out that the vulnerability has been known for over a year, with various experts previously highlighting the dangers of auto-downloading media files.

This is not the first time CertiK’s disclosures have been met with skepticism. In November 2023, CertiK reported a vulnerability in the Solana Saga smartphone, claiming that the device could be hacked to steal user data. However, these claims were disputed by Solana experts and the Blockchain community, who clarified that the issue was related to unlocking the smartphone’s bootloader—a feature available on many Android devices that requires physical access to be exploited.

Conclusion

The recent findings by CertiK underscore the ongoing challenges in ensuring the security of digital communication platforms such as Telegram. While the vulnerability has sparked debate within the crypto and wider tech community, it serves as a reminder of the importance of staying vigilant and adopting safe practices when using these applications. Disabling auto-downloads, keeping software up to date, and being cautious about the sources of downloaded files are critical steps users can take to protect themselves against potential threats.

As the digital landscape continues to evolve, so do the tactics of malicious actors. It is crucial for users and developers alike to remain informed and proactive in addressing security vulnerabilities to safeguard personal and sensitive information.

$400 Million Acquisition Tops $200 Million-Plus Venture Investments Amid Weak Corporate Activity

Incrypted tracked 19 investment deals from Sept. 1 to Sept. 12, 2026, with disclosed amounts in 13 transactions exceeding $804 million, including about $204 million in venture funding.

7 Min Read
Bitcoin ETFs End Three-Week Inflow Streak With $463M Outflows

SoSoValue said U.S. spot Bitcoin ETFs recorded $462.73 million in outflows from September 8–11, 2026, ending three consecutive inflow weeks, while spot Ethereum ETFs received $197.11 million, extending inflows to…

2 Min Read
OpenAI Launches ChatGPT for Financial Sector

OpenAI introduced ChatGPT for Financial Services, combining GPT-6 Astra with financial data, research and modeling tools for investment banking and equity research workflows developed with Morgan Stanley and Evercore.

5 Min Read
Sam Bankman-Fried Appeals Conviction to US Supreme Court, Seeks New Trial

Sam Bankman-Fried asked the US Supreme Court to overturn his fraud conviction, order a new trial and reverse an $11 billion forfeiture order, arguing it is an excessive fine.

6 Min Read
Colosseum to Host Hackathon for Projects Across Blockchain Ecosystems

Colosseum’s Crypto World’s Fair hackathon will run from September 14 to October 12, 2026, featuring multiple blockchain ecosystems and more than $3.3 million in prizes and investment, according to a…

4 Min Read