Telegram Desktop Critical Flaw Lets Attackers Take Over Accounts
Key Takeaways A critical vulnerability (CVE-2026-107181) in Telegram Desktop could allow attackers to steal local files and compromise user accounts. The flaw affects Telegram Desktop versions prior...
Key Takeaways
- A critical vulnerability (CVE-2026-107181) in Telegram Desktop could allow attackers to steal local files and compromise user accounts.
- The flaw affects Telegram Desktop versions prior to 7.2.9.
- Successful exploitation requires a user to click a specially crafted external link.
- The vulnerability carries a high severity rating of 8.6 (CVSS 4.0).
- A patch is available in Telegram Desktop version 7.2.9 and later.
Critical Flaw in Telegram Desktop Exposes Users to Account Takeover and File Theft
A recently disclosed vulnerability in Telegram Desktop, identified as CVE-2026-107181, poses a significant risk of local file exfiltration and account compromise. This critical flaw, affecting versions preceding 7.2.9, enables attackers to seize control of user accounts and access sensitive local files through a single click on a malicious external link. The vulnerability has been assigned a CVSS 4.0 score of 8.6, classifying it as high severity.
Table Of Content
Security researcher Beaksec detailed the technical specifics of the vulnerability in a write-up published on October 3, 2026, and subsequently updated on October 7. VulnCheck officially assigned the CVE on the latter date. The attack vector targets Telegram’s local session data, making an account takeover feasible, particularly if the victim has not configured a local passcode for their Telegram application.
Technical Breakdown of the Vulnerability
The core of the weakness resides in how Telegram Desktop processes links initiated from outside the application. When an instance of Telegram is already active, subsequent attempts to open a link from an external source—such as a web browser—are routed to the running application via an inter-process communication (IPC) channel.
This IPC mechanism suffered from an improper handling of record delimiters (CWE-143). An attacker could embed a specific character, typically used to separate data records, within a crafted URL. This manipulation would trick Telegram into misinterpreting a portion of the malicious link as an executable command, rather than benign URL data.
According to ThreatWire’s research, this injected command could then exploit an outdated internal helper function. This legacy helper, originally designed for release publishing, possessed the capability to read local files and transmit them to a chat without requiring explicit user permission or confirmation, effectively bypassing critical security checks.
The consequence is direct file theft, where Telegram itself becomes the conduit for data exfiltration. Furthermore, the compromise of session files could grant an attacker unauthorized access to the victim’s logged-in account. It’s important to distinguish this from other Telegram account hijacking methods, such as those exploiting voicemail vulnerabilities, which operate through different vectors.
Attack Scenarios and Conditions
The researcher successfully demonstrated this attack chain on Windows, utilizing Telegram Desktop version 6.9.3, and confirmed its persistence up to version 7.2.8. While the CVE broadly covers Telegram Desktop, the provided proof-of-concept did not extend to macOS or Linux environments.
For the attack to succeed, the malicious link must be opened from an external application, such as a web browser. Links clicked within the Telegram application itself follow a distinct processing path and are not susceptible to this vulnerability. Additionally, a browser might prompt the user for permission before launching the desktop application, offering a potential layer of defense.
The demonstrated attack chain also relies on specific user settings, including automatic group file downloads and configurations that permit anyone to add the victim to a group. These prerequisites are crucial when evaluating the “one-click” nature of the claim. Similar download setting considerations have been highlighted in previous security advisories, such as those related to EvilVideo, though that issue impacted Telegram for Android rather than the desktop client.
Patch and Mitigation
Telegram addressed this vulnerability in commit db3405699f on September 16, subsequently releasing the patched version 7.2.9 on September 17. The update involved the removal of the deprecated helper function, proper escaping of the record separator character, and enhanced handling of mixed record types within the IPC channel.
It is noteworthy that the official release notes for version 7.2.9 only mentioned a rendering fix, without explicitly detailing the security vulnerability. No specific vendor security advisory has been publicly identified in the reporting. The CVSS 3.1 score for this flaw is 8.1, while CVSS 4.0 assigns a score of 8.6, both reflecting the same underlying issue.
As of October 9, the available reporting indicates no known exploitation of this vulnerability in the wild, nor has it been listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. The public proof-of-concept serves to demonstrate feasibility rather than confirmed attacks. Users should not mistake the public write-up for independent confirmation of active exploitation.
What You Should Do
- Update Immediately: Ensure all Telegram Desktop installations are updated to version 7.2.9 or newer without delay. This is the most critical step.
- Enable a Local Passcode: Implement a local passcode within Telegram Desktop to protect your session data, even if an attacker manages to access your local files.
- Disable Automatic Downloads: Navigate to your Telegram settings and disable automatic downloads for files, especially in groups.
- Restrict Group Invitations: Adjust your privacy settings to control who can add you to groups, limiting unsolicited invitations.
- Exercise Caution with External Links: Be highly suspicious of unexpected browser prompts asking to open Telegram Desktop, especially if they originate from unfamiliar sources or suspicious links.
- Review Active Sessions: If you suspect potential exposure, immediately end all other active Telegram sessions from your privacy settings and review your chat history for any unexpected file uploads.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.