Telegram Desktop Flaw Lets a Single Click Hijack Your Account
Telegram Desktop vulnerability allowed any user's file to be stolen

A two-part vulnerability in Telegram Desktop through 7.2.8 turns a clicked link into arbitrary file read. The first flaw is command injection in the local socket protocol: a semicolon inside a URL splits into extra commands. The second is the internal interpret: scheme, which reads any file and sends it to a chat without authorization. Together they exfiltrate the tdata encryption keys, enabling full account takeover. Fixed in 7.2.9.
So a crafted link does not arrive as one instruction: it arrives as several.