EN

MAX messenger’s TLS certificate was revoked — what this means for users

· · The Ateo Digital editorial team

MAX messenger’s TLS certificate was revoked — what this means for users

On the evening of June 5, 2026, the state messenger MAX had its TLS certificate revoked — this is a digital document without which a browser does not consider the connection to a site secure. Firefox already shows a large red warning, “Be careful. Something doesn’t look right”, when opening max.ru; Chrome shows a similar NET::ERR_CERT_REVOKED error.

The MAX app on iOS and Android also uses TLS to communicate with servers — there, users may see an instant connection drop, endless loading, or a “network error” message. The severity of the problem depends on how certificate pinning is implemented in the client and whether the system caches the OCSP response.

In this article we explain what exactly happened to the certificate, how this relates to MAX’s recent removal from the Apple App Store, what to expect in the coming days, and how a user can tell a real infrastructure failure from regional blocking.

In brief

  • On June 5, 2026, MAX (max.ru) had its TLS certificate revoked — browsers now block access.
  • Firefox and Chrome show a warning screen; Safari does not let users proceed.
  • The MAX apps on iOS and Android may crash, fail to load chats, or show network errors.
  • By our estimates, issuing and propagating a new certificate will take from two to seven days.
  • This is not blocking by Roskomnadzor — it is an infrastructure failure on MAX’s own side.
  • Context: a week earlier, Apple removed MAX from the App Store; new installations on iOS became impossible.

What happened to the MAX certificate

A TLS certificate confirms that max.ru is really the site it claims to be, not a fake. The certificate is issued by a certificate authority (CA), and the same authority can revoke it — for example, if the private key is compromised, if information about the domain owner has changed, or by decision of the owner itself.

When a certificate is revoked, information about the revocation is added to CRL (the certificate revocation list) and to OCSP (online status checking). Modern browsers pull this data in the background — so the switch to “not secure” does not happen instantly, but once the client updates its copy.

Why now

At the time of publication, neither MAX itself nor JSC “VK” (the service operator) had officially announced the exact reason for the revocation. Possible scenarios include a change of certificate authority, problems with auto-renew at the chosen CA, problems with the DNS CAA record, or an administrative decision.

What happens in the browser

Firefox uses its own OneCRL mechanism and updates the list of revoked certificates through a service update. Chrome relies on Google’s CRLSets. Because of this, the error may appear in different browsers with a delay of several hours between them — for some people max.ru may still open, while for others it already shows an alert.

How to understand what exactly broke

SymptomPossible causeWhat to check
Firefox: “Be careful. Something doesn’t look right” TLS certificate revocation, MAX confirmed through OneCRL Open the same site in another browser, check the date
Chrome: “NET::ERR_CERT_REVOKED The same revocation, confirmed through CRLSets Click “Advanced” — see the CA name and revocation date
Mobile app: endless loading Certificate pinning does not accept the new certificate Restart the app, turn the internet off and on
App: “no connection to server” TLS handshake fails at the validation stage Compare with behavior on another operator/Wi-Fi
Only on your operator — it works for others Not the certificate, but regional blocking/TSPU Check by operator through Freedom Checker

How to check right now

The symptoms of a revoked certificate and operator-level blocking look similar: in both cases, the request to the server fails. You can tell them apart by checking whether the behavior is the same across all operators and what the exact error is.

Freedom Checker regularly checks the availability of services through Russian telecom operators (MTS, MegaFon, Beeline, Tele2, Rostelecom) from different regions. If max.ru shows the same TLS error everywhere, this is an infrastructure certificate revocation, not operator blocking.

Check availability through Freedom Checker

Failure or blocking?

Right now, this is an infrastructure failure on MAX’s side, not blocking. The difference is simple:

  • A failure produces the same error across all operators and regions, usually with specific text about the certificate.
  • Blocking usually produces different symptoms: a timeout on one operator, an instant close on another, region-specific behaviour, no TCP response from the IP.

No regional blocking of MAX has been recorded at the moment — Roskomnadzor supports the launch of this messenger as part of the “state messenger” project, so blocking it at the TSPU level makes no sense.

Context: removal from the Apple App Store

A few days before the certificate revocation, Apple removed MAX from the Russian segment of the App Store. The decision was framed as a “violation of platform policies” — without detailed public explanations. Downloading MAX to a new iPhone in Russia is now impossible by the standard method.

These are two different events, but they are politically connected: both the removal and the certificate revocation are happening against the backdrop of tighter regulation and mandatory preinstallation of MAX on Russian-assembled smartphones. The timing gives grounds for theories about coordinated actions by Western platforms.

What users need to understand:

  • If MAX is already installed, it will remain on the phone. It will be removed only if you choose to remove it.
  • Updates through the App Store will not arrive until MAX returns to the catalog.
  • On Android, MAX is still available through RuStore and Google Play (at the moment).

What to do in the coming days

  • Do not ignore the “Not Secure” warning — this is not a browser glitch, but a real infrastructure situation.
  • Do not enter passwords or payment data on max.ru until a new certificate is issued.
  • If MAX stops working in the app, wait. The service will either get a new certificate or roll out a client update with an updated set of CAs.
  • Do not reinstall the app on iOS — it is not available for reinstallation from the App Store.
  • Have an alternative communication channel available during this period.
  • Check availability by operator if the problem seems local.

Conclusion

On the evening of June 5, MAX had its TLS certificate revoked — this is not blocking and not a “shutdown” of the service, but an infrastructure failure. Fixing this usually takes from several hours to several days, and sometimes up to a week if the CA requires new domain validation.

Together with the recent removal from the Apple App Store, the situation shows how strongly MAX depends on infrastructure decisions by Western companies (CA, App Store), even though the service is positioned as a “state messenger”. Until the certificate is updated, max.ru should not be used through a browser.

Check now