Telegram Desktop had one-click account takeover bug
Original: Telegram Desktop vulnerability allowed any user's file to be stolen
Why This Matters
IPC injection in a 1B-user messenger enabling silent session theft is a serious supply-chain risk.
A researcher found CVE-2026-107181 in Telegram Desktop ≤7.2.8: a crafted tg:// link exploited an unescaped semicolon in IPC to read arbitrary local files—including session files—and send them to an attacker's chat.
Security researcher 'beaksec' disclosed a high-severity vulnerability (CVE-2026-107181, CVSS 8.1) in Telegram Desktop that allowed a single clicked link to hand over a victim's account. The flaw lived in how Telegram handles its single-instance model: when a second process launches after clicking a tg:// link, it connects to a local socket and serializes the URL as text using semicolons as delimiters—then exits. The already-running instance deserializes that message, splitting on semicolons to read commands.
The problem: Telegram never escaped semicolons inside the URL itself. A crafted link could inject extra commands into that IPC channel, arriving as multiple separate instructions instead of one. The injected command reached an internal URI scheme called `interpret:`, which reads a file specified in an instruction file and forwards it to any chat—no confirmation prompt, no permission check. Chaining both flaws meant an attacker could steal Telegram's session files, achieving full account takeover. Exploitation required only that the victim click a link, for example one dropped into a group chat. The bug affected Windows (confirmed on 6.9.3) through version 7.2.8. Telegram patched it in 7.2.9 via commit db3405699f.