Research / Finding
Telegram iOS: bridge exposed to iframes F-TELEGRAM-WEBAPP-001
Read the full technical write-up →
Root cause, affected code and disclosure timeline.
At a glance Conditions A third-party iframe in a bot Web App can reach a bridge intended for the main frame. What to do Use a version containing the release-12.4 main-frame checks. The source-branch evidence does not verify rollout to every installed app. 1seal reading guide, reviewed 2026-09-25 against the linked records. Not a new vendor assessment or a device rollout check.
Fix and severity by source Source assessments remain separate. Different CVSS versions are not a revision of one another. Code fixes, released versions and deployed updates are distinct evidence.
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Read the evidence · View in research browse
Recorded evidence
—score not recorded
Telegram iOS Web App bridge exposed to third-party iframes
Fixed in: release-12.4
Fix recorded not counted
details
Finding IDs F-TELEGRAM-WEBAPP-001 Status patched CWE CWE-863, CWE-346 Fixed in release-12.4 Disclosure date 29 Mar 2026 Recorded severity medium F-TELEGRAM-WEBAPP-001: Access control. A subframe can reach a bridge intended for the main frame. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-TELEGRAM-WEBAPP-001
Security area (1seal assessment): Authorization. A subframe can reach a bridge intended for the main frame. Reviewed 24 Sep 2026.
—score not recorded
Telegram iOS Web App bridge exposed to third-party iframes
fixed publicly
details
Finding IDs F-TELEGRAM-WEBAPP-001 Status fixed publicly Reported via Telegram security contact Note public fix commit c5a0ad267cbd2a61a0d4548490f6af5521fa55df in release-12.4. see 1SEAL-2026-008. F-TELEGRAM-WEBAPP-001: Access control. A subframe can reach a bridge intended for the main frame. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-TELEGRAM-WEBAPP-001
Security area (1seal assessment): Authorization. A subframe can reach a bridge intended for the main frame. Reviewed 24 Sep 2026.
Clarify or correct this record privately . The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy .
How this page groups evidence This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules .