TL;DR
Get privacy and security gear delivered free with Prime
- Fast, free delivery on millions of items
- Prime Video, Amazon Music and more included
- Member-only deals all year
BeakSec reported a Telegram Desktop vulnerability that could let an attacker who persuaded a victim to click a crafted link read and send local files, including files used to access the victim’s account. The report says Telegram fixed the issue in version 7.2.9; the researcher identified versions through 7.2.8 as affected, with testing confirmed on Windows.
Security researcher BeakSec reported a Telegram Desktop vulnerability that could let an attacker steal local files after a victim clicked a crafted link, potentially including files used to access the victim’s Telegram account. The researcher said the flaw affected versions through 7.2.8 and was fixed in version 7.2.9; the reported testing was confirmed on Windows.
The report describes a chain involving two defects. When Telegram Desktop is already running, a newly launched instance passes a clicked link to the existing instance through a local socket. The link is serialized as text, but the report says Telegram did not escape the semicolon separator used to divide instructions. A semicolon included in a crafted link could therefore be treated as the start of another command when the running application parsed it.
That injection could reach Telegram’s internal interpret: URI scheme, according to BeakSec. The scheme was intended for an internal release-publishing workflow: an instruction file could specify a file to send and a destination chat. The researcher says this mechanism lacked a check that the request came from an authorized source and did not ask the user to confirm before sending the file.
BeakSec says the chain enabled arbitrary local file reading and exfiltration to an attacker-controlled chat. The report further says the researcher used it to obtain files associated with the victim’s login and described the result as an account takeover. The report lists the issue as CVE-2026-107181, with a CVSS 3.1 score of 8.1, rated High. These technical and impact details are claims in the researcher’s report; the supplied material does not include a separate Telegram statement confirming them.
How Link Handling Put Files at Risk
The reported issue matters because its trigger was a user clicking a link, rather than an attacker already having access to the victim’s computer or Telegram account. If the described chain worked as reported, an attacker could use a chat link to cause Telegram Desktop to read and send files without the victim seeing a file-transfer confirmation. That could expose sensitive information stored on the device.
The potential account impact raises the stakes beyond ordinary local file disclosure. BeakSec says files used for Telegram login could be taken and used in an account takeover. The report does not establish that every installation or operating system was affected in the same way, nor does it provide evidence about how widely the flaw was exploited. Readers using an affected version should treat the version boundary in the report as a reason to update, while recognizing that the details available here come from the researcher.
Telegram desktop security software
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
The Two Flaws Behind the Report
Telegram Desktop supports links using the tg: scheme. According to BeakSec, when a link is opened while Telegram is already active, a new process hands the link to the running process through a local socket. The receiving process reconstructs commands by splitting the text at semicolons. The report says the sender did not escape semicolons within a URL, allowing one link to be interpreted as multiple instructions.
Command injection alone was not enough to produce the reported file theft. The researcher says the injected instruction could use Telegram’s internal interpret: handler, which read a text instruction file and sent the file named in it to a specified chat. BeakSec identifies this release-publishing feature as the second defect in the chain: it was reachable through the injected command and, according to the report, did not verify authorization or request confirmation.
The report names versions through 7.2.8 as affected and version 7.2.9 as the fix, citing commit db3405699f. It says the vulnerability was confirmed on Windows using version 6.9.3. That test detail should not be read as proof that every listed version, platform or configuration was independently tested.
“The chain I found has two defects.”
— BeakSec, in the vulnerability report
file encryption software for Windows
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Scope and Exploitation Still Unclear
The supplied source material does not include a response from Telegram, a security advisory from the company, or independent verification of the researcher’s findings. It also does not establish whether attackers exploited the vulnerability outside the researcher’s demonstration, how many users may have been exposed, or whether all desktop operating systems were affected.
BeakSec’s report says the issue was confirmed on Windows with version 6.9.3 and gives an affected range through 7.2.8. The source does not spell out the testing basis for every version and platform in that range. It is also unclear from the supplied material whether Telegram has published further details about the patch, whether related code paths were reviewed, or whether any additional mitigations were issued.
As an affiliate, we earn on qualifying purchases.
Update to the Patched Release
BeakSec identifies Telegram Desktop 7.2.9 as the release containing the fix. Users should check their installed version and update through Telegram’s official distribution channel if they are running an earlier release. The report does not provide a separate company advisory or instructions for checking whether a device was affected.
Further clarity would depend on Telegram publishing or confirming its own technical advisory, including the supported-platform scope and any guidance for users who may have opened suspicious links. Until such information is available, the confirmed account in the supplied material remains the researcher’s description of the flaw and its reported fix.
As an affiliate, we earn on qualifying purchases.
Key Questions
What did the Telegram Desktop vulnerability allow?
BeakSec says a crafted link could exploit unsafe command parsing and an internal file-sending feature to read local files and send them to an attacker-controlled chat. The researcher also reported that files used for account access could enable an account takeover.
Which Telegram Desktop versions were reported as affected?
The report lists versions through 7.2.8 as affected and says the flaw was fixed in 7.2.9. BeakSec specifically says it confirmed the issue on Windows with version 6.9.3; the supplied source does not document testing of every version and platform.
Did exploiting the flaw require a victim to do anything?
Yes. The report describes a user clicking a crafted link as the trigger. It does not describe the vulnerability as requiring no user interaction.
Has Telegram confirmed the vulnerability or reported exploitation?
No Telegram statement or independent exploitation confirmation appears in the supplied material. The technical findings, impact assessment and fix details are attributed to BeakSec’s report.
What should Telegram Desktop users do?
Users should check that they are running version 7.2.9 or later, which BeakSec identifies as containing the fix, and update through an official Telegram distribution channel if needed.
Source: hn
Columbus Day / Indigenous Peoples' Day Picks
long weekend sales
As an affiliate, we earn on qualifying purchases.
