CVE-2020-12474: Telegram

Medium severity, CVSS 6.5. EPSS: 2.6% chance of exploitation in the next 30 days.

Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public URL or a group chat invitation URL.

Affected products

  • Telegram Telegram: up to and including 6.0.1
  • Telegram Telegram Desktop: up to and including 2.0.1

Published 2020-05-01. Last modified 2026-06-17.