hn.today

Telegram Desktop: one-click account takeover via IPC injection

beaksec.github.io8 points2 comments
Screenshot of Telegram Desktop: one-click account takeover via IPC injection

A vulnerability in Telegram Desktop’s single-instance IPC lets a clicked tg:// link inject extra commands into an already-running instance because the app serializes multiple instructions as semicolon-delimited text but never escapes semicolons inside URL query strings. That injection combines with an internal interpret: URI handler that reads a plain-text "instruction" file from disk and sends its referenced file to a chat without any authorization or user confirmation. Together these defects allow a remote attacker to turn a one-click link into arbitrary local file reads and exfiltration to an attacker-controlled chat. The issue affected Telegram Desktop through 7.2.8 (CVE-2026-107181), is rated High (CVSS 8.1), and was fixed in 7.2.9.

The exploit chain is practical: an attacker sends a crafted link in a group; when clicked, the new process hands OPEN:interpret:... commands to the running instance; the attacker supplies the instruction file by uploading it to the same group (Telegram Desktop auto-downloads received files up to 8 MiB into a predictable Downloads/Telegram Desktop path), or uses relative paths resolved from the app data folder. interpret: then reads arbitrary files and posts them to a channel the attacker controls. Reading tdata/key_datas suffices to recover the DEK/KEK encryption chain when users have no local passcode, allowing decryption of session authorization files and complete account takeover.

Read on beaksec.github.io2 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.