Research / Finding
Telegram iOS: TL parsing over-read F-TELEGRAM-TL-001
Read the full technical write-up →
Root cause, affected code and disclosure timeline.
At a glance Conditions Malformed TL data reaches a bounds check whose operator precedence permits a heap buffer over-read. What to do Use a version containing the release-12.4 bounds-check correction. The source-branch evidence does not verify rollout to every installed app. 1seal reading guide, reviewed 2026-09-25 against the linked records. Not a new vendor assessment or a device rollout check.
Fix and severity by source Source assessments remain separate. Different CVSS versions are not a revision of one another. Code fixes, released versions and deployed updates are distinct evidence.
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Read the evidence · View in research browse
Recorded evidence
5.3medium
heap buffer over-read in TL deserialization from operator precedence bug
Fixed in: release-12.4
Fix recorded not counted
details
Finding IDs F-TELEGRAM-TL-001 Status patched CWE CWE-125 Fixed in release-12.4 Disclosure date 29 Mar 2026 Recorded severity medium CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N F-TELEGRAM-TL-001: Memory safety. TL parsing can read beyond an input buffer. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-TELEGRAM-TL-001
Security area (1seal assessment): Memory safety. TL parsing can read beyond an input buffer. Reviewed 24 Sep 2026.
—score not recorded
heap buffer over-read in TL deserialization from operator precedence bug
fixed publicly
details
Finding IDs F-TELEGRAM-TL-001 Status fixed publicly Reported via Telegram security contact Note public fix commit 8e9cd79855683efb9a3cbf14a1ecd637cfbf7b54 in release-12.4. see 1SEAL-2026-007. F-TELEGRAM-TL-001: Memory safety. TL parsing can read beyond an input buffer. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-TELEGRAM-TL-001
Security area (1seal assessment): Memory safety. TL parsing can read beyond an input buffer. Reviewed 24 Sep 2026.
Clarify or correct this record privately . The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy .
How this page groups evidence This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules .