Image: Beaksec
TL;DR
Security researchers publicly disclosed a high-severity vulnerability in the Telegram Desktop application. This Telegram Desktop account takeover flaw enables remote attackers to steal session keys via a single click. Consequently, developers released an emergency patch to secure the messaging client.
- CVE: CVE-2026-107181
- CVSS: 8.6 (High Β· CVSSv4)
- Product: Telegram Desktop
- Affected: < 7.2.9
- Impact: Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via interpret: Scheme
- Status: No confirmed exploitation yet
- Patched in: 7.2.9
- EPSS: 0.3% (30-day)
- Action: Update to 7.2.9 now
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysWhy It Matters
Telegram boasts over 900 million active users globally. Millions of these individuals rely on the desktop client for daily communication. Therefore, a Telegram Desktop account takeover poses a massive privacy risk. Attackers can hijack active sessions to access private chats and contacts. Furthermore, researchers publicly disclosed the proof-of-concept exploit code. This public disclosure dramatically increases the immediate risk of widespread attacks. Threat actors can easily copy the methodology to target vulnerable users. The availability of detailed exploit mechanics means organizations must prioritize patching immediately. Additionally, a compromised account allows attackers to impersonate victims and spread malicious links. Corporate environments face elevated risks because employees often link personal accounts to work devices. Data exfiltration through this method bypasses standard two-factor authentication protections. The attacker clones the session directly from the local disk.
How The Attack Works
The attack exploits an inter-process communication flaw within the application sandbox. Specifically, the vulnerability involves an IPC record-separator injection. Telegram Desktop uses a local socket to communicate with already-running instances. According to the BeakSec analysis, “Telegram Desktop hands clicked links to its own already-running instance over a local socket, as text, and never escapes the character it uses to separate commands.”
Therefore, an attacker can craft a malicious link containing unescaped semicolons. This causes the application to split the link into multiple separate instructions. The injected command then triggers an internal URI scheme called “interpret:”. This specific scheme reads local files and sends them to a designated chat without user confirmation. As the researchers observed, “Together they turn a clicked link into arbitrary file read.”
To execute the attack, an adversary first sends a disguised text file to a group chat. The application automatically downloads this file to a predictable default directory. Next, the attacker sends a crafted hyperlink to the victim. When the victim clicks the link, the local socket reads the unescaped semicolons. The client then processes the injected commands. Ultimately, the application uploads the user’s session keys directly to the attacker. The attacker imports these files to clone the active session completely. The cloned session grants the attacker full access to messages and media.
Exploitation Status
Security analysts published a full technical breakdown alongside proof-of-concept exploit code. However, cybersecurity authorities have not confirmed any active exploitation of this flaw in the wild.
Affected Versions
This vulnerability affects Telegram Desktop versions up through 7.2.8. Researchers verified the flaw specifically on Windows installations.
Patch And Mitigation Steps
Users must update their clients to version 7.2.9 or later immediately. Developers fixed the issue by completely removing the vulnerable “interpret:” scheme. They also implemented strict escaping for record separators.
If you cannot update immediately, you should adjust your application settings. First, enable the “ask where to save each file” option. This setting stops the automatic downloading of malicious instruction files. Next, limit your group privacy settings. Restrict group invitations to known contacts only. Finally, you should configure a local desktop passcode. A strong passcode encrypts your local session data. This renders stolen session files useless to the attacker.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!