VYPR
Unrated severityNVD Advisory· Published Apr 20, 2021· Updated Aug 3, 2024

CVE-2021-30496

CVE-2021-30496

Description

The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied message (e.g., in the Persian language) into a channel or group. The crash occurs in MtProtoKitFramework. NOTE: the vendor's perspective is that "this behavior can't be considered a vulnerability."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Telegram iOS 7.6.2 crashes when a victim pastes a specially crafted Persian-language message from an attacker into a channel or group.

Vulnerability

The vulnerability resides in the MtProtoKitFramework of Telegram for iOS, version 7.6.2. A remote authenticated attacker can cause a denial of service (application crash) by sending a message containing certain Persian characters to a channel or group. The crash is triggered when the victim pastes the attacker-supplied message into any channel or group within the app [1].

Exploitation

An attacker must be an authenticated Telegram user. They craft a message (e.g., in the Persian language) that exploits the parsing flaw in MtProtoKitFramework. The attacker sends this message to a channel or group where the victim is a member. The victim then copies and pastes the message into the same or another channel or group. The paste action immediately crashes the Telegram app [1].

Impact

Successful exploitation causes the Telegram iOS app to crash, resulting in a temporary denial of service. The app can be relaunched without data loss. No code execution, privilege escalation, or persistent damage has been reported [1].

Mitigation

No official fix has been released; the vendor stated that “this behavior can't be considered a vulnerability.” Users are advised to avoid pasting untrusted messages, especially those containing non-Latin characters. As of the publication date (2021-04-20), no patch is available, and the issue is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.