Telegram has fixed a zero-day vulnerability in its Windows desktopthat could have been used to bypass security warnings and automatically launch Python scripts.
See also: Telegram 10.5.0 update: Improved Calls, Brand New Experience

In recent days, rumors have been circulating on X and hacker forums about an alleged remote code execution vulnerability in Telegram for Windows.
While some of these posts claimed it was a zero-click flaw, the videos showing the alleged security warning bypass and RCE vulnerability clearly show someone clicking on shared media to launch the Windows calculator.
Telegram quickly disputed the zero-day claims, stating that they “cannot confirm that such a vulnerability” and that the video is likely a hoax.
However, the next day, a PoC was shared on the XSS, explaining that a typo in the source code for Telegram for Windows could be exploited to send Python .pyzw that bypass security warnings when clicked.
See also: Telegram: Its purchases are boosting phishing attacks
This caused Python to automatically execute the file without warning from Telegram, as it does with other executable files, and it should have been executed for this file if it wasn't a typo.

To make matters worse, the Telegram zero-day proof of concept disguised the Python file as a shared video, along with a thumbnail, which could be used to trick users into clicking on the fake video to watch it.
In a statement to BleepingComputer, Telegram rightly disputes that the bug was a zero-click flaw, but confirmed that it had fixed the “issue” in Telegram for Windows to prevent Python scripts from automatically launching when clicked. This was a server -side fix .
See also: Avoid Telegram Peer-to-Peer
How can systems be protected from Zero-Day attacks?
Protecting systems from Zero-Day exploits, such as the one discovered in Telegram, requires a multi-layered approach. First, it is important to keep systems up to date. This means applying the latest security updates and patches regularly. Second, using security software, such as antivirus and firewalls, can help detect and prevent Zero-Day attacks. These tools can identify and block attacks before they cause damage. Third, user education is crucial. Users need to be aware of the tactics used by attackers, such as phishing , and how to recognize them. Finally, using techniques such as sandboxing and isolating systems can reduce the risk of Zero-Day attacks.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
