A vulnerability was identified where sending a specifically crafted string of Unicode characters (or a malformed .tgs animated sticker file) causes the Telegram client to enter an infinite loop or experience a buffer overflow, resulting in an immediate application crash. The "crush" occurs as soon as the message is rendered in the chat view, even without user interaction.
: You see a weird text overlap. You triple-tap the screen. crush bug telegram
An attacker can effectively "lock" a group chat for all members until the malicious message is deleted via the API or a different platform (e.g., Web K/Z which might be immune). Commentary: "Crush Bug Telegram" — a small phrase,
Me: Trying to act cool and mysterious. My brain the second my crush replies: System Error. Does not compute. ✅ Telegram crashes immediately when you open a