Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
MATCHBOIL Malware Uses Cloudflare to Hide C2 Servers, Delivers Backdoor Payloads
October 9, 2026
Telegram Desktop Critical Flaw Lets Attackers Take Over Accounts
October 9, 2026
Top 10 Container Image Scanners for 2026
October 9, 2026
Home/Vulnerabilities/Telegram Desktop Critical Flaw Lets Attackers Take Over Accounts
Vulnerabilities

Telegram Desktop Critical Flaw Lets Attackers Take Over Accounts

Key Takeaways A critical vulnerability (CVE-2026-107181) in Telegram Desktop could allow attackers to steal local files and compromise user accounts. The flaw affects Telegram Desktop versions prior...

Marcus Rodriguez
Marcus Rodriguez
October 9, 2026 4 Min Read
3 0

Key Takeaways

  • A critical vulnerability (CVE-2026-107181) in Telegram Desktop could allow attackers to steal local files and compromise user accounts.
  • The flaw affects Telegram Desktop versions prior to 7.2.9.
  • Successful exploitation requires a user to click a specially crafted external link.
  • The vulnerability carries a high severity rating of 8.6 (CVSS 4.0).
  • A patch is available in Telegram Desktop version 7.2.9 and later.

Critical Flaw in Telegram Desktop Exposes Users to Account Takeover and File Theft

A recently disclosed vulnerability in Telegram Desktop, identified as CVE-2026-107181, poses a significant risk of local file exfiltration and account compromise. This critical flaw, affecting versions preceding 7.2.9, enables attackers to seize control of user accounts and access sensitive local files through a single click on a malicious external link. The vulnerability has been assigned a CVSS 4.0 score of 8.6, classifying it as high severity.

Table Of Content

  • Key Takeaways
  • Critical Flaw in Telegram Desktop Exposes Users to Account Takeover and File Theft
  • Technical Breakdown of the Vulnerability
  • Attack Scenarios and Conditions
  • Patch and Mitigation
  • What You Should Do

Security researcher Beaksec detailed the technical specifics of the vulnerability in a write-up published on October 3, 2026, and subsequently updated on October 7. VulnCheck officially assigned the CVE on the latter date. The attack vector targets Telegram’s local session data, making an account takeover feasible, particularly if the victim has not configured a local passcode for their Telegram application.

Technical Breakdown of the Vulnerability

The core of the weakness resides in how Telegram Desktop processes links initiated from outside the application. When an instance of Telegram is already active, subsequent attempts to open a link from an external source—such as a web browser—are routed to the running application via an inter-process communication (IPC) channel.

This IPC mechanism suffered from an improper handling of record delimiters (CWE-143). An attacker could embed a specific character, typically used to separate data records, within a crafted URL. This manipulation would trick Telegram into misinterpreting a portion of the malicious link as an executable command, rather than benign URL data.

According to ThreatWire’s research, this injected command could then exploit an outdated internal helper function. This legacy helper, originally designed for release publishing, possessed the capability to read local files and transmit them to a chat without requiring explicit user permission or confirmation, effectively bypassing critical security checks.

The consequence is direct file theft, where Telegram itself becomes the conduit for data exfiltration. Furthermore, the compromise of session files could grant an attacker unauthorized access to the victim’s logged-in account. It’s important to distinguish this from other Telegram account hijacking methods, such as those exploiting voicemail vulnerabilities, which operate through different vectors.

Attack Scenarios and Conditions

The researcher successfully demonstrated this attack chain on Windows, utilizing Telegram Desktop version 6.9.3, and confirmed its persistence up to version 7.2.8. While the CVE broadly covers Telegram Desktop, the provided proof-of-concept did not extend to macOS or Linux environments.

For the attack to succeed, the malicious link must be opened from an external application, such as a web browser. Links clicked within the Telegram application itself follow a distinct processing path and are not susceptible to this vulnerability. Additionally, a browser might prompt the user for permission before launching the desktop application, offering a potential layer of defense.

The demonstrated attack chain also relies on specific user settings, including automatic group file downloads and configurations that permit anyone to add the victim to a group. These prerequisites are crucial when evaluating the “one-click” nature of the claim. Similar download setting considerations have been highlighted in previous security advisories, such as those related to EvilVideo, though that issue impacted Telegram for Android rather than the desktop client.

Patch and Mitigation

Telegram addressed this vulnerability in commit db3405699f on September 16, subsequently releasing the patched version 7.2.9 on September 17. The update involved the removal of the deprecated helper function, proper escaping of the record separator character, and enhanced handling of mixed record types within the IPC channel.

It is noteworthy that the official release notes for version 7.2.9 only mentioned a rendering fix, without explicitly detailing the security vulnerability. No specific vendor security advisory has been publicly identified in the reporting. The CVSS 3.1 score for this flaw is 8.1, while CVSS 4.0 assigns a score of 8.6, both reflecting the same underlying issue.

As of October 9, the available reporting indicates no known exploitation of this vulnerability in the wild, nor has it been listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. The public proof-of-concept serves to demonstrate feasibility rather than confirmed attacks. Users should not mistake the public write-up for independent confirmation of active exploitation.

What You Should Do

  • Update Immediately: Ensure all Telegram Desktop installations are updated to version 7.2.9 or newer without delay. This is the most critical step.
  • Enable a Local Passcode: Implement a local passcode within Telegram Desktop to protect your session data, even if an attacker manages to access your local files.
  • Disable Automatic Downloads: Navigate to your Telegram settings and disable automatic downloads for files, especially in groups.
  • Restrict Group Invitations: Adjust your privacy settings to control who can add you to groups, limiting unsolicited invitations.
  • Exercise Caution with External Links: Be highly suspicious of unexpected browser prompts asking to open Telegram Desktop, especially if they originate from unfamiliar sources or suspicious links.
  • Review Active Sessions: If you suspect potential exposure, immediately end all other active Telegram sessions from your privacy settings and review your chat history for any unexpected file uploads.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Top 10 Container Image Scanners for 2026

Next Post

MATCHBOIL Malware Uses Cloudflare to Hide C2 Servers, Delivers Backdoor Payloads

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Anthropic’s New OSS Scanner Identifies Open-Source Vulnerabilities
October 9, 2026
Top 10 IaC Security Tools for 2026
October 9, 2026
Microsoft: PKI, HSMs, Security Appliances Must Prepare for Post-Quantum Authentication
October 9, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us