Telegram's Windows application had a critical vulnerability that allowed the execution of Python scripts with a typo in certain file extensions. Attackers could disguise these scripts as video files and run them on user interaction. Telegram deployed a server-side fix and tagged the files with the ".untrusted" extension.

2m read time From infosecwriteups.com
Post cover image
Table of contents
Exploring the vulnerabilityDemonstration

Sort: