Dangerous vulnerability in Telegram Desktop: any file can be stolen with one click
What you MUST NOT do and how to protect yourself:
• Do not keep using versions earlier than 7.2.9 — update the client immediately. If you use an unofficial client, temporarily switch to the official one until an update is released.
Download:
• Windows / macOS / Linux: official website or GitHub.
• Windows: Microsoft Store.
• macOS: App Store.
• Linux: Flathub, Snapcraft.
Advice for users of older clients:
• Links can be dangerous: whenever you click a link, read the pop-up window carefully — if Telegram shows an unusual structure in the link (for example, one starting with tg://), do not open it.
• Do not use the client without a local passcode: enabling one encrypts the session files in the tdata directory, preventing immediate account hijacking even if those files are leaked.
What is the issue?
A vulnerability has been discovered in Telegram Desktop clients earlier than version 7.2.9 (CVE-2026-107181). Because the ; delimiter was not escaped, parameters in tg:// links were interpreted as separate IPC commands. Using the interpret: handler, an attacker could cause files from the system to be sent covertly to their channel, without the user’s confirmation, when the user clicked a specially crafted link.
The main risk
The danger is not limited to stealing tdata session files and hijacking accounts. Exploiting the vulnerability makes it possible to covertly steal absolutely any files on the computer that the user can access: documents, saved browser sessions, SSH keys, system configurations, or cryptocurrency wallets.
#security #desktop #vulnerabilities
Post #92194
324
