Skip to main content
HIGH

CVE-2019-10044

CVSS v3

8.8

HIGH

EPSS Score

3.3 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters exist in the same domain name, and the available font has an identical representation of characters from different alphabets.

Technical details

Published
2019-03-25

Frequently asked questions

What is CVE-2019-10044?

Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters exist in the same domain name, and the available font has an identical representation of characters from different alphabets.

Is CVE-2019-10044 actively exploited?

Active exploitation of CVE-2019-10044 has not been confirmed. Its EPSS score was 3.3% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-10044?

CVE-2019-10044 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2019-10044 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key