Telegram Desktop Flaw Lets a Single Click Hijack Your Account

Telegram Desktop vulnerability allowed any user's file to be stolen

Telegram Desktop Flaw Lets a Single Click Hijack Your Account

A two-part vulnerability in Telegram Desktop through 7.2.8 turns a clicked link into arbitrary file read. The first flaw is command injection in the local socket protocol: a semicolon inside a URL splits into extra commands. The second is the internal interpret: scheme, which reads any file and sends it to a chat without authorization. Together they exfiltrate the tdata encryption keys, enabling full account takeover. Fixed in 7.2.9.

So a crafted link does not arrive as one instruction: it arrives as several.

More from this day

2026-10-10