hn.today

Telegram Desktop vulnerability allowed any user's file to be stolen

beaksec.github.io179 points74 comments
Screenshot of Telegram Desktop vulnerability allowed any user's file to be stolen

A flaw in Telegram Desktop’s single-instance IPC allows a clicked tg:// link to turn into multiple commands because the client serializes instructions as text using an unescaped semicolon separator. A second running instance deserializes bytes by splitting on semicolons, so a semicolon inside a URL becomes an injected command. That injected command can reach an internal interpret: URI handler that reads a plaintext “instruction” file from disk and sends the named file to a chat without any authorization or user confirmation. Because Telegram Desktop auto-downloads group attachments (up to 8 MiB) into a predictable directory (e.g., Downloads\Telegram Desktop) and interpret: accepts relative paths, an attacker can deliver an instruction.txt via chat and then trigger OPEN:interpret:path via a crafted tg:// link (for example using ../../../Downloads/Telegram%20Desktop/instructions.txt) to exfiltrate files.

By stacking multiple OPEN:interpret commands in one injected line an attacker can retrieve arbitrary local files - including tdata/key_datas and authorization/session files - and send them to an attacker-controlled channel. Telegram’s local storage uses DEK/KEK wrapping; with the default configuration (no local passcode) the KEK is derived from an empty password, so reading key_datas plus the session file yields full account credentials and enables takeover. The issue affected Telegram Desktop through 7.2.8 (confirmed on Windows), is CVE-2026-107181, scored 8.1, and was fixed in 7.2.9 (commit db3405699f).

Read on beaksec.github.io74 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.