ESET researchers discovered a zero-day vulnerability for the Android version of Telegram that was sold for sale in an underground forum post on June 6, 2024 for an unspecified price. By abusing the vulnerability, which the ESET research team named EvilVideo, attackers can share malicious Android payloads through Telegram channels, groups, and chats and make them appear as multimedia files. It is reported that the vulnerability only applies to Android Telegram versions 10.14.4 and earlier. After the ESET research team reported it to Telegram, the vulnerability was fixed on July 11, 2024, and Telegram released version 10.14.5 on July 11, and notified the ESET research team by email.