Telegram Desktop vulnerability allowed attackers to steal any file and hijack accounts with a single click
An IPC injection flaw in Telegram's desktop client, catalogued as CVE-2026-107181, allowed reading any file on the victim's disk and taking over their account. The fix shipped in September but went unnoticed.
What the flaw allowed
A researcher who publishes under the name BeakSec found a chain of flaws in Telegram Desktop that turned a single click into a complete account takeover. Catalogued as CVE-2026-107181, with a severity of 8.1 (high) on the CVSS 3.1 scale (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N), the flaw affected every version up to 7.2.8, with exploitation confirmed on Windows in version 6.9.3.

The stated impact is direct: remote reading of any local file, exfiltrated to a chat controlled by the attacker, with account hijacking as a consequence. No installation or permission grant was required: it was enough to click a link while being in a group with the attacker.
Two processes, one socket, and an unescaped separator
Telegram Desktop registers the tg:// scheme with the operating system. When you click a link of that type, the system launches a new Telegram process, passing the URL as an argument. If Telegram is already running, the system opens a second process anyway: it's up to the app itself to detect the redundancy.
To do this, the new process tries to connect to a local socket where the already-open instance acts as a server. Upon finding a connection, it serializes the URL as text and sends it over the socket, in the format OPEN:url;, using a semicolon to separate instructions. The problem is that this character is never escaped: if the received URL already contains a ;, the instance receiving the data splits the string at the wrong point and sees two instructions where there should be one.
A link like tg://x?a=1;OPEN:interpret:instructions.txt becomes, on the receiving end, two separate commands: open tg://x?a=1 and then process interpret:instructions.txt as if it were another legitimate link. This is command injection caused by the lack of escaping for the separator, according to the analysis published in the original write-up.
The interpret: scheme and the missing check
The interpret: scheme is not registered with the operating system; it exists only inside Telegram's code and was created for internal use, in a routine that published official builds to Telegram's own channels. A script read an instructions file in this format and had Telegram send the indicated file to a channel, with a caption:
from: 1234567890
channel: 1987654321
file: out/Release/deploy/6.9.3/tsetup.6.9.3.exe
caption: TDesktop at 12.06.26The function that processes this, InterpretSendPath, reads any file at the indicated path and sends it to the specified channel, without asking for confirmation. The check for who is authorized to trigger this action only runs if the from: line is present in the file, and simply omitting it skips the entire verification. When this function could only be triggered from the command line, the risk was low: anyone who already has access to the machine doesn't need this route to read files. The problem arises when command injection via the socket makes interpret: reachable from a link clicked by someone else.
From file read to account hijacked
To exploit the flaw, the attacker needs to place the instructions file on the victim's disk at a predictable path. The simplest route is to send it as an attachment in a group: by default, Telegram Desktop automatically downloads files up to 8 MiB received in groups (unlike channels, where automatic download comes disabled), saving them with their original name in a fixed folder.
Because interpret: accepts relative paths resolved from Telegram's working directory, the attacker doesn't even need to know the Windows username: a path like interpret:../../../Downloads/Telegram%20Desktop/instructions.txt already reaches the default downloads folder deterministically.
From there, the full PoC chain described by BeakSec follows these steps:
- The attacker creates a supergroup and adds the victim (Telegram's default privacy settings allow this without confirmation).
- Posts three instruction files in the group, each pointing to a sensitive file in Telegram's
tdatafolder and to the attacker's channel as the destination. - Sends an innocuous https link in the same chat, whose server redirects (302) to a malicious
tg://link with three chainedinterpret:commands. - The victim clicks, the browser follows the redirect, Telegram opens the link, the injection fires, and the three files are uploaded to the attacker's group, without any confirmation dialog.
The three stolen files (tdata/key_datas, the MTProto authorization file, and a data index) are enough to reconstruct the victim's tdata folder on another machine and open their session, because by default Telegram Desktop doesn't use a local passcode: the key that protects the data is derived from an empty string and a salt that sits, with no encryption at all, inside key_datas.
How the link reaches the victim
A technical detail explains why the attack depends on an https link rather than a direct tg:// link inside Telegram itself: clicks on tg:// made from within a chat are handled internally by the already-open process and never pass through the socket, so there's nothing to inject. A regular https link, however, opens in the system's default browser, because Telegram Desktop doesn't have a built-in browser, and it's only on that path, via an HTTP redirect controlled by the attacker, that the malicious tg:// link is delivered.
What this changes for everyday Telegram Desktop users
Team groups on Telegram are common among Brazilian product and engineering teams for sharing logs, error screenshots, .env snippets, API tokens, and even SSH keys on an emergency basis. This flaw shows that merely being present in a group with a malicious person, with no action beyond clicking some link, is already enough to expose any file on the machine, including ones that never passed through Telegram itself.
The official fix is straightforward:
- Update to version 7.2.9 or later. This is the only measure that actually closes the problem.
- Turn on "ask where to save each file" in settings, disabling automatic downloads: without this, the instructions file never reaches the disk.
- Restrict who can add you to groups to contacts only, since the theft depends on sending the files to a channel or supergroup controlled by the attacker.
- Set a real local passcode: it doesn't prevent the files from being stolen, but it makes the stolen session useless without it.
Silent fix and disclosure timeline
The flaw was reported to the Zero Day Initiative (ZDI) on June 25, 2026. Telegram fixed the issue independently on September 16, 2026, in commit db3405699f, published in version 7.2.9 the following day. ZDI closed the case as already fixed on September 30, releasing disclosure rights to the researcher, who published the full analysis on October 3 and had the CVE assigned on October 7, 2026.
The 7.2.9 changelog mentions only "a rendering fix," and the commit that eliminates the flaw was internally named as the removal of a legacy path-interpretation helper, with no public security advisory accompanying the release. In addition to completely removing the interpret:// scheme and the InterpretSendPath function, the fix now escapes the separator character in the socket protocol using hexadecimal encoding prefixed by %, so that a semicolon in the data can no longer become a command boundary.
Translated from the Brazilian Portuguese original · Read the original
C2y removes 45 of the roughly 100 undefined behaviors in the C standard
In a talk at Kernel Recipes 2026, researcher Martin Uecker showed how the C committee is reducing the language's undefined behaviors without giving up the compatibility that still underpins kernels and embedded systems today.