← Today's brief

Security · Updated 10 Oct, 08:32 am IST

Telegram Desktop link bug let attackers steal local files and take accounts

Image: Hacker News (100+ points)

Why it matters for readers: It demonstrates how a single clickable link can exploit poor input handling to read local files and send them out.

  • Telegram Desktop handed clicked links to its running instance over a local socket without escaping the command-separator character, enabling command injection.1
  • The injected command could invoke an internal URI scheme (interpret:) that reads a named file and sends it to a chat without verifying the requester, enabling arbitrary local file read and exfiltration.1
  • The flaw could be triggered by a single clicked link and led to remote arbitrary local file read and potential account takeover; rated CVSS 8.1 (High).1
  • The issue was confirmed on Windows and affects Telegram Desktop through version 7.2.8; it was fixed in version 7.2.9 (commit db3405699f).1

Get a brief like this every morning

Uzha reads hundreds of sources and gives you the stories that matter for your work, with every source linked. Free.

Get started