Critical vulnerability uncovered in Telegram Desktop: A single click on a malicious link can instantly steal any local files and user sessions. The crypto community is urged to update immediately.
Security researcher beaksec (Emiliano Versini) recently disclosed a critical vulnerability (CVE-2026-107181) affecting Telegram Desktop versions 7.2.8 and earlier. Attackers can craft malicious tg:// links; when users click these links via external platforms such as browsers, an IPC injection enables reading of arbitrary local files—including tdata session files—and exfiltrating them to an attacker’s channel, potentially leading to account takeover. The flaw has been patched in Telegram Desktop
@tonmelonfest
Post #12957
1