Security · Updated 10 Oct, 08:32 am IST
Telegram Desktop link bug let attackers steal local files and take accounts

Why it matters for readers: It demonstrates how a single clickable link can exploit poor input handling to read local files and send them out.
- Telegram Desktop handed clicked links to its running instance over a local socket without escaping the command-separator character, enabling command injection.1
- The injected command could invoke an internal URI scheme (interpret:) that reads a named file and sends it to a chat without verifying the requester, enabling arbitrary local file read and exfiltration.1
- The flaw could be triggered by a single clicked link and led to remote arbitrary local file read and potential account takeover; rated CVSS 8.1 (High).1
- The issue was confirmed on Windows and affects Telegram Desktop through version 7.2.8; it was fixed in version 7.2.9 (commit db3405699f).1
Get a brief like this every morning
Uzha reads hundreds of sources and gives you the stories that matter for your work, with every source linked. Free.
Get started