Telegram's vulnerability footprint, though modest in volume relative to major platform vendors, reflects the prominence of its messaging and voice-communication applications across consumer and enterprise deployments. The exposure spans its desktop, mobile, and web clients and centers on weakness classes including out-of-bounds writes, sensitive-information leakage, type confusion, and cleartext storage—issues that recur in real-time communication software where protocol handling, encryption implementation, and state management are security-critical. A meaningful share of the vendor's disclosures reach serious severity, reflecting the sensitivity of user data and the authentication layers these products protect. Defenders should prioritize updates to end-user clients and monitor for protocol-layer flaws; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Telegram over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40532CRITICAL Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension. | Sep 6, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-17613CRITICAL Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKS5 protocol. | Sep 28, 2018 | 9.8 | 30 | NO | NO |
CVE-2019-10044HIGH Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attack when displaying messages containing U | Mar 25, 2019 | 8.8 | 28 | NO | NO |
CVE-2017-17715HIGH The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal via a pathname obtained in a file-transfe | Dec 16, 2017 | 8.8 | 28 | NO | NO |
CVE-2024-7014HIGH EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting
versions 10.14.4 and older. | Jul 23, 2024 | 8.1 | 27 | NO | NO |
CVE-2018-20436HIGH The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composing a chat message, before that | Dec 24, 2018 | 8.1 | 26 | NO | NO |
CVE-2020-17448HIGH Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filena | Aug 11, 2020 | 7.8 | 25 | NO | NO |
CVE-2018-17780MEDIUM Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because of an unsafe default behavior in | Sep 29, 2018 | 6.5 | 24 | NO | NO |
CVE-2023-26818MEDIUM Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag. | May 19, 2023 | 5.5 | 23 | NO | NO |
CVE-2018-17231HIGH Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "Edit color palette" search that triggers | Sep 19, 2018 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Telegram.
Media articles that mention a CVE ID that affects a product developed by Telegram — matched by CVE ID, not by vendor name.