: Open your device Settings > Apps > Telegram > Storage and tap Clear Cache .

A message containing a video or image with a corrupted thumbnail header can cause the app’s image decoder to fail catastrophically when generating the preview.

The platform has since stated that "no private data was exposed and that the records contain information already available to the public," but the incident nonetheless underscores the need for improved security hygiene and vigilance.

Zero-click vulnerabilities represent the most dangerous category of security flaws. As the name suggests, these exploits require no action from the victim—simply receiving a malicious message or file can compromise the device.

If your mobile app crashes instantly upon opening, log into ( web.telegram.org ) or download the Telegram Desktop application on a computer. Desktop environments handle text rendering differently and often ignore the mobile exploit code. Step 2: Delete the Offending Chat or Message Once logged in via web or desktop: Locate the group, bot, or user that sent the crash weapon.

: Specially crafted .GIF or .MP4 files designed to exploit the app's media previewer.

Here are the most common types of crush bugs found in Telegram:

: Go to Settings > Privacy and Security and set "Messages" to "My Contacts" only to prevent unknown senders from sending malicious stickers.

Telegram's billion-user base makes it an attractive target for attackers, and the platform's popularity means that vulnerabilities can have widespread consequences. By staying informed about emerging threats, keeping applications updated, and implementing basic security measures, users can significantly reduce their risk exposure.

The rendering engine gets stuck trying to determine the spacing or direction (left-to-right vs. right-to-left) of the characters.

While Telegram has stated the feature "doesn’t need to be fixed" and has argued that functionality is not a security issue, other analysts note that geolocation data is often shared with greater precision than users realize, and that "legacy users may have 'never turned on yet already authorized,' while new users can easily be passively activated during the onboarding flow."