AI NewsDev toolsReported

Telegram Desktop had a one-click account takeover through its own URL handler

A researcher who writes as BeakSec published the chain that turns a clicked link into a stolen Telegram account, fixed in 7.2.9.

AI News

Editorial2 min read

LinkedInX
Diagram of the chain from a clicked link to a victim's session files

Image: BeakSec

Why it mattersAnyone running Telegram Desktop below 7.2.9 can lose their account from a single clicked link, so the team should upgrade the client on every machine today.

A link that opens a desktop app is not the end of the user's exposure, because the app has to work out what to do with it, and the work can go wrong.

A researcher writing as BeakSec published the chain for CVE-2026-107181 on 3 October 2026. The flaw sits in how Telegram Desktop hands a clicked tg:// link to its own already-running copy. The handoff goes over a local socket, flattened to text, with a semicolon between commands and no escaping on the parts that came from the link. A link that contains a semicolon of its own splits into two instructions on the way in. BeakSec reported it through ZDI on 25 June 2026. The fix shipped in Telegram Desktop 7.2.9 on 17 September 2026, under commit db3405699f. The CVE was assigned on 7 October, four days after the writeup.

From a clicked link to the account

The injection on its own closes the app, which is harmless. The reach comes from a second URL scheme inside the client, interpret:, which was built so a release script could post the signed Windows installer to a Telegram channel from the command line. That handler reads a text file off the disk, picks a file path out of it, and sends that file to a chat. The handler never checked who asked for the action.

Chained with the injection, interpret: becomes a way to read any file on the disk and send it to a chat under the attacker's control. The post walks the reader through using it to grab the three files in Telegram's data folder (key_datas, the authorization file, and the index) that together hold the account. Default settings make it reliable: files sent into a group auto-download below 8 MiB and land under a predictable path. The client has no local passcode by default, so the encryption that wraps the data derives its key from an empty password and the salt sitting beside it.

Severity, scope and mitigation

BeakSec records the impact as "remote arbitrary local file read, exfiltrated to an attacker-controlled chat; account takeover", at CVSS 8.1 High. All versions up to 7.2.8 are affected, confirmed on Windows 6.9.3. The delivery needs one click, from outside Telegram, because an in-app tg:// link is handled in-process and never reaches the socket. The post names four mitigations in order: upgrade to 7.2.9, turn on "ask where to save each file" so the instruction file never lands on disk, limit who can add you to groups, and set a local passcode so a stolen session cannot be opened.

Fixing the two defects took the Telegram team a few lines each: the single-instance socket now percent-encodes the record separator, and the Support::InterpretSendPath helper was removed with its URI scheme. The 7.2.9 changelog mentions a rendering fix and nothing else, and no advisory was published with it. If an engineering team ships a desktop app with a URL handler, the lesson is in the two gates that opened together: a text channel that trusted the shape of its own messages, and a privileged helper that trusted whoever reached it.

Source

Telegram Desktop: one-click account takeover via IPC injection, BeakSec.

Reported byBeakSec

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX
Start a project