CVE-2021-47793
Telegram Desktop vulnerability analysis and mitigation

Overview

CVE-2021-47793 is a denial of service (DoS) vulnerability in Telegram Desktop version 2.9.2 that allows attackers to crash the application by sending an oversized message payload. The vulnerability was assigned by VulnCheck and published to NVD on January 15, 2026, despite the CVE identifier suggesting a 2021 origin. Only Telegram Desktop 2.9.2 is listed as a confirmed affected version. It carries a CVSS v3.1 base score of 7.5 (High) as scored by VulnCheck (VulnCheck Advisory, Exploit-DB).

Technical details

The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), meaning the application fails to impose adequate constraints on buffer allocation when processing incoming message payloads. An attacker can craft a message containing approximately 9 million bytes and paste or send it through the Telegram Desktop messaging interface, triggering an application crash due to uncontrolled resource consumption. No authentication or special privileges are required to send such a message to another Telegram user. A public proof-of-concept exploit is available on Exploit-DB (Exploit-DB, VulnCheck Advisory).

Impact

Successful exploitation results in a crash of the Telegram Desktop application on the victim's system, causing a loss of availability for the messaging client. The impact is limited to availability — there is no confidentiality or integrity impact, and the vulnerability does not enable code execution or data exfiltration. Affected users running Telegram Desktop 2.9.2 would experience service disruption until the application is restarted, and repeated exploitation could constitute persistent harassment or targeted disruption (VulnCheck Advisory).

Exploitation steps

  1. Identify target: Confirm the target is running Telegram Desktop version 2.9.2 on their system.
  2. Generate oversized payload: Create or obtain a text buffer of approximately 9 million bytes (e.g., using a script to generate a string of that length).
  3. Send the payload: Paste the oversized buffer into the Telegram Desktop message input field and send it to the target user's chat, or use the Telegram API to programmatically deliver the oversized message.
  4. Trigger crash: Upon receipt and rendering of the oversized message payload, the target's Telegram Desktop application crashes due to uncontrolled buffer allocation, resulting in a denial of service (Exploit-DB, VulnCheck Advisory).

Indicators of compromise

  • Logs: Telegram Desktop application crash logs or Windows Event Viewer entries showing unexpected termination of the Telegram.exe process around the time of message receipt.
  • Network: Unusually large message payloads (approaching or exceeding several megabytes) observed in Telegram network traffic.
  • Process: Sudden, unexpected termination of the Telegram.exe (Windows) or equivalent Telegram Desktop process without user-initiated action.
  • File System: Crash dump files (e.g., .dmp files) generated in the Telegram Desktop application directory or system temp folder following the crash event.

Mitigation and workarounds

Users should update Telegram Desktop to any version released after 2.9.2, as the vulnerability is specific to that version. No official patch advisory from Telegram has been published, but upgrading to the latest available release is the recommended remediation. As a temporary workaround, organizations can monitor and restrict oversized message payloads at network boundaries, or restrict Telegram Desktop usage until an update is applied (VulnCheck Advisory).

Additional resources


SourceThis report was generated using AI

Related Telegram Desktop vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-17448HIGH7.8
  • Telegram Desktop logoTelegram Desktop
  • net-im/telegram-desktop
NoYesAug 11, 2020
CVE-2020-12474MEDIUM6.5
  • NixOS logoNixOS
  • telegram
NoYesMay 01, 2020
CVE-2021-36769MEDIUM5.3
  • NixOS logoNixOS
  • telegram-desktop
NoYesJul 17, 2021
CVE-2021-47793MEDIUM4.6
  • Telegram Desktop logoTelegram Desktop
  • cpe:2.3:a:telegram:telegram_desktop
NoNoJan 16, 2026
CVE-2020-25824LOW2.4
  • Telegram Desktop logoTelegram Desktop
  • net-im/telegram-desktop
NoYesOct 14, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management