Cybersecurity researchers from BeakSec discovered a dangerous vulnerability in the desktop version of Telegram, which allowed attackers to steal files from the device and gain access to other people's accounts. The flaw, identified as CVE-2026-107181 and rated 8.6 out of 10 on the CVSS scale, was caused by an error in processing internal links of the tg:// format. The problem affected all versions of Telegram Desktop up to 7.2.9 and was fixed by developers on September 17.

The problem was caused by incorrect handling of special characters in links opened through the application. When clicking on a tg:// link, the operating system sends a command to the running client via a local socket. Telegram Desktop separated commands in this channel with a semicolon, but did not escape this character within the address itself.
An attacker could embed additional instructions into the link that would call the service handler interpret:. This component allowed reading files from the disk and sending them to a chat without any user confirmation. The main target of the attack was session files from the tdata folder — with their help, an attacker could log into an account without re-authorization. In the absence of a user-set local passcode, the stolen tdata folder gives full control over the account. Similarly, if the exact path was known, other files accessible to the client could be stolen: documents, SSH keys, or configuration data.
BeakSec researchers reported the problem to the developers on June 25 through the Zero Day Initiative program. The vulnerability was fixed in Telegram Desktop version 7.2.9, released on September 17. The developers removed the insecure service handler and changed the command transfer mechanism, but this was not mentioned in the official update description — the release was accompanied only by a note about fixing animation rendering.
This was fixed in mid-September, and all current versions of Telegram Desktop are safe. There was practically no risk, as an attacker would have to convince the user to click on a suspicious link, then confirm it, and also know the exact system path to the target file.
No confirmed cases of the vulnerability being used in real attacks have been recorded yet. Users are advised to update Telegram Desktop to version 7.2.9 or newer, and to set a local passcode to encrypt session files.
Read more on the topic:
Never miss our newsAdd this site to your preferred sources to see us more oftenAdd on Google

















