Kimi K3 Uncovers Near Zero‑Click RCE in Telegram Desktop and iOS, Bypassing ASLR
Security researcher Chaofan Shou revealed that Kimi K3’s AI model discovered a near zero‑click remote code execution flaw in Telegram’s desktop (Windows/macOS/Linux) and iOS clients, bypassing ASLR and requiring only a crafted data packet, with the exploit just one gadget away from full RCE.
Event Overview
On July 23, 2026, security researcher Chaofan Shou announced that the AI model Kimi K3, developed by Moonshot AI, identified a high‑severity vulnerability affecting Telegram’s desktop (Windows, macOS, Linux) and iOS clients.
Core Findings
Zero‑click vulnerability in Telegram desktop and iOS.
Enables arbitrary command execution with ASLR successfully bypassed.
The exploit is one gadget away from achieving full remote code execution.
No user interaction is required; a crafted data packet triggers the exploit.
Technical Analysis: Near Zero‑Click Attacks
Zero‑Click vs. Near Zero‑Click
Traditional exploits rely on convincing a user to click a malicious link or open a file. A true zero‑click flaw requires no user action at all, while a near zero‑click flaw may need an extremely limited interaction, such as receiving a specially crafted message.
What ASLR Bypass Means
Address Space Layout Randomization (ASLR) randomizes memory addresses to hinder exploitation. Kimi K3’s analysis shows that the researchers mapped the memory layout of the Telegram client, identified a suitable gadget, and constructed an exploit chain that circumvents ASLR, bringing the attack within reach of full remote code execution.
Attack Scenario
A victim could simply receive a message in a group chat; the malicious payload would execute automatically without any clicks, rendering conventional user‑training advice ineffective.
Impact Scope
The vulnerability affects:
Telegram desktop (Windows, macOS, Linux)
Telegram iOS
Telegram serves over 900 million monthly active users. Successful exploitation could allow attackers to remotely control devices, exfiltrate contacts, chat history, files, monitor user activity, and move laterally within internal networks.
Broader Vulnerability Discoveries by Kimi K3
Beyond Telegram, Kimi K3 uncovered real‑world flaws in other popular software:
Redis
32 agents collaborated for 27 minutes to find multiple RCE bugs in the latest Redis releases.
Generated exploit code covering versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0.
Chrome and WeChat
Identified authentic vulnerabilities in the newest Chrome browser and WeChat client.
These findings illustrate that AI‑driven vulnerability research is expanding from single targets to a wide range of applications, lowering the barrier to discovering exploitable bugs.
Mitigation Recommendations
For Telegram Users
Monitor official Telegram security updates closely.
Upgrade to the latest client version as soon as it is released.
Avoid joining unknown groups or channels.
For the Industry
Acknowledge the real threat posed by AI‑generated vulnerability research.
Accelerate collaborative AI security research initiatives.
Reevaluate vulnerability response processes and the time window for mitigation.
Video Demonstration
A technical video demonstrates the near zero‑click RCE exploit discovered by Kimi K3.
Signed-in readers can open the original source through BestHub's protected redirect.
This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactand we will review it promptly.
Black & White Path
We are the beacon of the cyber world, a stepping stone on the road to security.
How this landed with the community
Was this worth your time?
0 Comments
Thoughtful readers leave field notes, pushback, and hard-won operational detail here.
