Saifeldeen Aziz

Stickers r-lot-tie Handle: Vulns, Bypasses, and Telegram’s Zero-Click Attack Surface

Abstract

Earlier this year, ZDI discovered a critical Telegram vulnerability with an initial CVSS score of 9.8, which was later reduced to 7.0. Telegram argued that server-side mitigations made the vulnerable client-side code unreachable. This talk presents our independent year long research on Telegram showing why that assumption does not hold. The talk covers multiple new 0-click vulnerabilities in telegram, multiple bypasses for Telegram’s server-side and client-side mitigations and the exploit primitives we developed along the way.

We begin with LLM-orchestrated fuzzing of rlottie, Telegram’s animated sticker rendering library, which uncovered multiple memory-corruption vulnerabilities affecting Telegram clients across iOS, Android, and Desktop. The surprise was not just the bugs themselves, but how heavily Telegram’s risk model depended on keeping malicious stickers out through server-side validation. We then show how we discovered separate logic vulnerabilities in Telegram’s sticker delivery and validation flows and chained them together to make the supposedly unreachable rlottie attack surface a ripe vulnerability playground.

Finally, we chain these vulnerabilities against Telegram for iOS to achieve code execution and examine the resulting exploit’s limitations. Even in response to our findings, Telegram continues to rely primarily on reachability mitigations while the vulnerable rendering code remains deployed across its official clients. We leave the audience with a difficult question: should this model, a zero-click capability controlled entirely by a secure messaging provider, be considered a mitigation, an architectural risk, or something closer to a backdoor?

BIO

Saifeldeen is a vulnerability researcher specializing in low-level security. He got into offensive security through CTF competitions, starting with binary exploitation, and has spent seven years working across reverse engineering, firmware analysis, source code auditing, and exploit development. He has discovered zero-day vulnerabilities in widely deployed products from vendors including PAX Technology, Huawei, ZTE, VMware, and TP-Link, covering memory corruption, command injection, and privilege escalation. More recently, he has been expanding his research from embedded targets into larger, more complex software and attack surfaces.