The Spectrum Dispatch News

technology

Telegram Desktop vulnerability allowed account takeover via malicious links

A flaw in how Telegram Desktop handled inter-process communication let attackers steal user files and session data with a single clicked link.

Telegram Desktop vulnerability allowed account takeover via malicious links

Telegram Desktop versions through 7.2.8 contained a vulnerability that could allow attackers to steal arbitrary files from a user’s computer and take over their account, according to a security analysis posted on the Beak Security blog.

Telegram Desktop vulnerability allowed account takeover via malicious links

The vulnerability exploited two separate defects in Telegram Desktop’s handling of clicked links. When a user clicked a link, Telegram Desktop passed it to an already-running instance through a local socket using a simple text-based format. Each instruction ended with a semicolon as a separator.

The first flaw was an unescaped separator character. If a crafted link contained a semicolon in the URL itself, Telegram would interpret it as multiple separate commands rather than a single instruction. For example, a link like tg://x?a=1;CMD:quit would be serialized and transmitted to the running instance, which would then parse it as two separate commands: OPEN:tg://x?a=1 and CMD:quit.

The second flaw involved an internal URI scheme called interpret: that was originally designed for Telegram’s internal use during software releases. This scheme could read a file from disk and send it to a chat without any authorization checks or user confirmation. The interpret: handler would read an instruction file specifying which file to send and which chat to send it to, then perform the action automatically.

By combining these two defects, an attacker could craft a malicious link that injected an interpret: command. When a victim clicked the link, it would trigger the file-reading functionality and exfiltrate files to an attacker-controlled chat. According to the analysis, attackers could distribute an instruction file to victims as a chat attachment, then send a crafted link that would execute that instruction file and steal sensitive data, including session files containing login credentials.

The vulnerability affected Windows versions of Telegram Desktop and was confirmed on version 6.9.3 and other releases through 7.2.8. It was assigned CVE-2026-107181 with a CVSS severity score of 8.1 (High). Telegram fixed the issue in version 7.2.9, according to the security researcher who discovered it.

Key facts

  • Telegram Desktop through 7.2.8 allowed attackers to read arbitrary files from a user’s disk via a malicious link
  • The attack exploited an unescaped separator character in Telegram’s inter-process communication protocol
  • An internal interpret: URI scheme designed for software releases lacked authorization checks
  • Attackers could exfiltrate session files containing login credentials, enabling account takeover
  • The vulnerability was fixed in Telegram Desktop 7.2.9

Sources

← All posts