Post #92214 223 Oct 11, 2026, 05:16 UTC Forwarded from Nika's thoughts on... (Nika) https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/additional context beaksec Telegram Desktop: one-click account takeover via IPC injection An unescaped separator in Telegram Desktop’s single-instance IPC lets one clicked link read arbitrary files off the disk and send them to the attacker, session files included.