Telegram Security & Privacy Scorecard

Android

68
Overall trust score
Acceptable
60
Security
75
Privacy

Messages are delivered through Google's Firebase infrastructure, and the device interacts with Google Play Services and SafetyNet. Payments processed through Stripe follow standard financial data handling. Usage data touches several Google-operated services, though no advertising or behavioral tracking SDKs are present.

Best for

Everyday messaging with standard Google integrations

Findings

  • 0 critical
  • 0 high
  • 0 medium
  • 0 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • OAuth Client ID Remote Override Vulnerability
  • Regular Messages Stored in Unencrypted Database
  • Unencrypted Credentials in SharedPreferences

Top privacy issues

  • Auth Tokens Backed Up to Google Drive
  • External Storage Media Unencrypted
  • WebView Third-Party Cookies Enabled

Full analysis

Telegram

Version: 12.3.1 (Build 63852)
Scan Date: January 31, 2026

What This Means for You

Messages are delivered through Google's Firebase infrastructure, and the device interacts with Google Play Services and SafetyNet. Payments processed through Stripe follow standard financial data handling. Usage data touches several Google-operated services, though no advertising or behavioral tracking SDKs are present.

Recommendation: Use With Caution

Best For: Everyday messaging with standard Google integrations

Key Findings

Data Security - 9 findings (1 critical, 1 high, 4 medium, 3 low)

Network Security - 2 findings (1 medium, 1 low)

Code Safety - 0 findings

Privacy - 1 finding (1 medium)

Privacy Concerns

What Data is Collected

Telegram collects device identifiers and usage information through Google Play Services and Firebase. Payment details are handled by Stripe when users make in-app purchases. User location may be accessed through Google Maps when location-sharing features are used.

Third-Party Data Sharing

User data is shared with the following third-party services:

  • Google (Firebase Cloud Messaging, Firebase Remote Config, Google Play Services, Google Play Billing, Google Maps, ML Kit, SafetyNet): Message delivery, app configuration, device security checks, and billing.
  • Stripe: Processing of any payments made within the app.
  • ZXing: QR code reading, processed locally on the device.
  • NanoHTTPD: Local network functionality within the app.

No advertising networks or behavioral profiling services are embedded in this build.

Understanding the Scores

Category Score
Security 60/100
Privacy 75/100
Data Security 50/100
Network Security 85/100
Code Safety 70/100
Data Collection 100/100
Data Sharing 90/100
User Control 100/100

Positive Security Features

  • Data collection exposure is minimal: the app scores 100/100 for Data Collection, reflecting that it requests only what is needed for core functionality.
  • Users retain strong control over their data, reflected in a perfect User Control score of 100/100.
  • No advertising or behavioral tracking services are included in this version of the app.

Areas for Improvement

  • Local data stored on the device is not fully protected, meaning sensitive information could be exposed if someone gained physical access to the device.
  • Some network communications could be made more robust to better protect user data while it travels between the device and Telegram's servers.
  • Certain internal operations could be handled more securely to reduce risk if the app is running on a rooted or compromised device.

About This Analysis

This scorecard is generated through automated static analysis of the Android application binary. It reflects the security and privacy posture of this specific version and build.

App Details

Field Value
App Name Telegram
Package ID org.telegram.messenger
Version 12.3.1 (Build 63852)
Scan Date January 31, 2026
Platform Android

Versions & scan history

ScanDateOverall score
#1 (current) 68/100