Researchers discover security flaws in Telegram encryption protocol

Telegram
(Image credit: Shutterstock)

Researchers from the University of London's Royal Holloway have discovered several flaws in the MTProto protocol used by the popular encrypted messaging app Telegram.

While end-to-end encryption (E2EE) is available in one-on-one chats, the MTProto protocol is used in the service's group chats (also known as cloud chats) as well as when users don't opt-in for E2EE. MTProto is Telegram's version of transport level security (TLS) which is used to secure data in transit and to protect users from man-in-the middle attacks.

One of the security flaws discovered by Royal Holloway's researchers allowed an attacker on the network to reorder messages coming from a client to Telegram's servers. Although this flaw isn't particularly dangerous, the researchers did note that it was trivial to carry out.

The researchers also took a deeper look into Telegram's clients for Android, iOS and desktop where they discovered code that could be potentially be used to target user messages, although the content within would remain protected.

Still secure

Royal Holloway's researchers discovered a total of four vulnerabilities in Telegram's MTProto protocol and its clients and disclosed them to the company's development team back in April.

In the time since, Telegram has updated its encrypted messaging app and none of the flaws now pose a risk to the company's users.

In a new blog post, Telegram provided further details on the researchers' work and the changes it has made to patch the flaws, saying:

“The latest versions of official Telegram apps already contain the changes that make the four observations made by the researchers no longer relevant. Overall, none of the changes were critical, as no ways of deciphering or tampering with messages were discovered.”

Via Gadgets360

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Android phone malware
This nasty Android malware is posing as the Telegram Premium app
A VPN runs on a mobile phone placed on a laptop keyboard
Major new online tunneling vulnerability could put millions of devices at risk
Young woman using mobile phone
Best encrypted messaging app for Android of 2025
Telegram
New Golang malware is hijacking Telegram to help itself spread
Trojan
WhatsApp patches security flaw which let hackers install spyware
Security
Experts warn millions of email servers could be vulnerable to attack
Latest in Security
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Latest in News
Citroen 2CV
The retro EV resurgence is in full swing, as Citroen confirms the iconic 2CV will return with batteries
Hugging Snap
This AI app claims it can see what I'm looking at – which it mostly can
Apple iPhone 16 Pro Max REVIEW
The latest batch of leaked iPhone 17 dummy units appear to show where glass meets metal on the new designs
Hornet swings their weapon in mid air
Hollow Knight: Silksong could potentially launch this year and I reckon it could be a great game for an Xbox handheld
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Cassian looking at someone off-camera from a TIE fighter cockpit in Andor season 2
Star Wars: Andor creator is taking a stance against AI by canceling plans to release its scripts, and I completely get why