I clicked on a suspicious Telegram link a bot sent me, and my phone started downloading something. Am I screwed? I deleted and blocked the bot right away, but what’s the worst-case scenario here? Could they be in my phone already stealing my accounts? I couldn’t stop the download because it finished so fast. I can’t find anything suspicious in the file app…
Edit: I found the download. It’s a PNG file of the ‘picture’ that the AI sent. Could anything else have been hidden in there?
There have been rare bugs where specially crafted images could trigger malware, like the Stagefright bug from years ago. But those are usually targeted at high-value individuals.
There was a Telegram vulnerability a while back with videos, but I don’t think it’s for images. Probably nothing to worry about, but keep an eye out for anything odd.