Kimi K3 Uncovers Near Zero‑Click RCE in Telegram Desktop and iOS, Bypassing ASLR

Security researcher Chaofan Shou revealed that Kimi K3’s AI model discovered a near zero‑click remote code execution flaw in Telegram’s desktop (Windows/macOS/Linux) and iOS clients, bypassing ASLR and requiring only a crafted data packet, with the exploit just one gadget away from full RCE.

Black & White Path
Black & White Path
Black & White Path
Kimi K3 Uncovers Near Zero‑Click RCE in Telegram Desktop and iOS, Bypassing ASLR

Event Overview

On July 23, 2026, security researcher Chaofan Shou announced that the AI model Kimi K3, developed by Moonshot AI, identified a high‑severity vulnerability affecting Telegram’s desktop (Windows, macOS, Linux) and iOS clients.

Core Findings

Zero‑click vulnerability in Telegram desktop and iOS.

Enables arbitrary command execution with ASLR successfully bypassed.

The exploit is one gadget away from achieving full remote code execution.

No user interaction is required; a crafted data packet triggers the exploit.

Technical Analysis: Near Zero‑Click Attacks

Zero‑Click vs. Near Zero‑Click

Traditional exploits rely on convincing a user to click a malicious link or open a file. A true zero‑click flaw requires no user action at all, while a near zero‑click flaw may need an extremely limited interaction, such as receiving a specially crafted message.

What ASLR Bypass Means

Address Space Layout Randomization (ASLR) randomizes memory addresses to hinder exploitation. Kimi K3’s analysis shows that the researchers mapped the memory layout of the Telegram client, identified a suitable gadget, and constructed an exploit chain that circumvents ASLR, bringing the attack within reach of full remote code execution.

Attack Scenario

A victim could simply receive a message in a group chat; the malicious payload would execute automatically without any clicks, rendering conventional user‑training advice ineffective.

Impact Scope

The vulnerability affects:

Telegram desktop (Windows, macOS, Linux)

Telegram iOS

Telegram serves over 900 million monthly active users. Successful exploitation could allow attackers to remotely control devices, exfiltrate contacts, chat history, files, monitor user activity, and move laterally within internal networks.

Broader Vulnerability Discoveries by Kimi K3

Beyond Telegram, Kimi K3 uncovered real‑world flaws in other popular software:

Redis

32 agents collaborated for 27 minutes to find multiple RCE bugs in the latest Redis releases.

Generated exploit code covering versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0.

Chrome and WeChat

Identified authentic vulnerabilities in the newest Chrome browser and WeChat client.

These findings illustrate that AI‑driven vulnerability research is expanding from single targets to a wide range of applications, lowering the barrier to discovering exploitable bugs.

Mitigation Recommendations

For Telegram Users

Monitor official Telegram security updates closely.

Upgrade to the latest client version as soon as it is released.

Avoid joining unknown groups or channels.

For the Industry

Acknowledge the real threat posed by AI‑generated vulnerability research.

Accelerate collaborative AI security research initiatives.

Reevaluate vulnerability response processes and the time window for mitigation.

Video Demonstration

A technical video demonstrates the near zero‑click RCE exploit discovered by Kimi K3.

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

RCETelegramZero-clickKimi K3ASLR bypassAI Vulnerability Discovery
Black & White Path
Written by

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.