Static

Telegram Desktop vulnerability allowed any user's file to be stolen

First reported by Beaksec.github ·

The signal ●○○○ Compiled by AI from Beaksec.github and Hacker News
Why you might care

Your Telegram session files can now be stolen via a malicious link, potentially leading to account takeover.

What happened

A critical vulnerability in Telegram Desktop, identified as CVE-2026-107181, allowed attackers to steal arbitrary user files, including session files, through a single clicked link. The exploit chains two flaws: an IPC injection vulnerability and an insecure interpretation of internal URI schemes. Specifically, an unescaped semicolon in a crafted link sent via chat could be interpreted as a command separator by Telegram Desktop's inter-process communication (IPC) mechanism. This injection allows an attacker to trigger Telegram's internal 'interpret:' URI scheme. This scheme, intended for internal use, could be leveraged to read any file on the victim's system and send its contents to an attacker-controlled chat. The vulnerability affects Telegram Desktop versions prior to 7.2.9 and was confirmed on Windows. The exploit can be chained to achieve account takeover by stealing session files.

What it means

The identified vulnerability in Telegram Desktop, CVE-2026-107181, hinges on a combination of an unescaped separator in its IPC mechanism and the mishandling of the 'interpret:' URI scheme. By sending a specially crafted link, an attacker can exploit Telegram Desktop's communication protocol between separate processes to inject commands. This injection allows them to trigger an internal function that reads specified files from the victim's local system and exfiltrates them to a chat controlled by the attacker, bypassing standard security checks and user confirmation. The ability to read session files directly facilitates account takeover.

This exploit highlights a significant security gap in how applications handle inter-process communication and internal URI schemes, particularly when data is serialized and deserialized across process boundaries. The flaw underscores the critical need for robust input validation and authorization checks even for internal functionalities. For users, it means that clicking on seemingly innocuous links in Telegram chats can have severe consequences, potentially compromising their account security and personal data. The fix, available in version 7.2.9, emphasizes the rapid response required for such critical vulnerabilities.

AI-written summary. May contain errors.