VYPR
Unrated severityNVD Advisory· Published Jul 16, 2021· Updated Aug 4, 2024

CVE-2021-36769

CVE-2021-36769

Description

A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop before 2.8.8. An attacker can cause the server to receive messages in a different order than they were sent a client.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Telegram before 7.8.1 (Android), 7.8.3 (iOS), and 2.8.8 (Desktop) allows network attackers to reorder client messages, enabling manipulation of message sequence.

Vulnerability

A message reordering vulnerability exists in Telegram's MTProto protocol, affecting Android versions before 7.8.1, iOS versions before 7.8.3, and Telegram Desktop before 2.8.8 [1]. The server does not enforce the order in which messages are received from a client, allowing an attacker to alter the sequence of messages.

Exploitation

An attacker with network access (e.g., on the same Wi-Fi or an ISP) can intercept the encrypted messages sent from a client to the Telegram server. By reordering the packets, the attacker can cause the server to process messages in a different order than intended. The attack is trivial to carry out and does not require decryption of the messages [1].

Impact

The attacker can alter the perceived sequence of messages in a conversation, potentially changing the meaning of the dialogue. For example, the order of statements like 'I say yes to' and 'all the pizzas' versus 'I say no to' and 'all the crimes' can be swapped, leading to confusion or misrepresentation. The impact is limited to message ordering; confidentiality and integrity of individual messages are not compromised [1].

Mitigation

Telegram addressed this issue in version 7.8.1 for Android, 7.8.3 for iOS, and 2.8.8 for Telegram Desktop [1]. Users should update to the latest version to mitigate the vulnerability. No workaround is available for older versions.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.