Kimi K3 is reported to have a zero-click command execution bug in Telegram apps
jedisct1 · x · 2026-07-23
A quoted post says Kimi K3 has a zero-click arbitrary command execution issue in Telegram Desktop and the iOS app, with ASLR pinned and “one gadget away from full RCE.” The reply simply reacts with “Welp.”
Related event: Kimi K3 Zero-Click Vulnerability Reported(2 posts)→
More from Safety
- Aidan Clark says safety techniques are easier to undo once they’re known — _aidan_clark_ · 2026-07-23
- Aidan Clark backs partnerships to safety-harden external models, not share the methods — _aidan_clark_ · 2026-07-23
- Researchers disclose one-click ChatGPT Workspace Agents hijack, fixed by OpenAI in 4 days — rez0__ · 2026-07-23
- AI education has to move beyond prompts and into context, verification, and judgment — Astrokanu · 2026-07-23
- Post-quantum security starts with knowing where your cryptography lives — moniquejmorrow · 2026-07-23
- Email agents need pre-model defenses because the inbox is the easiest attack surface — kumard3 · 2026-07-23