LiMP VPN
← All news

Telegram Desktop Flaw Stole Files After a Single Click

Telegram Desktop Flaw Stole Files After a Single Click

In short: security researchers at BeakSec found a critical flaw in Telegram Desktop (Windows and other desktop builds), CVE-2026-107181, rated 8.6 out of 10 on CVSS. A specially crafted tg:// link could make the client silently upload local files — including session files from the tdata folder — to a chat controlled by an attacker, with no confirmation prompt. That could lead to full account takeover. Telegram closed the hole in version 7.2.9, released September 17, 2026; a public technical write-up and a working proof-of-concept surfaced in early October.

What happened

Researchers at BeakSec found the bug and disclosed it through the Zero Day Initiative (ZDI) program back on June 25, 2026 — the public technical write-up went live October 3 and was updated October 7. The flaw sits in the interpret: scheme handler inside the Core::Sandbox component of the Telegram Desktop client: unescaped semicolons in tg:// links caused the app to misparse commands passed through inter-process communication (IPC), letting part of the link be interpreted as a file-upload instruction.

In practice, a link that looked ordinary — one the victim clicked from a browser or a message — triggered a hidden command inside the already-running Telegram client: upload specific local files to a chat the attacker chose. No confirmation was requested from the user.

Why the attack on tdata matters

The real target wasn't random documents but the tdata folder, where Telegram Desktop stores session files. With them, an attacker could log into someone else's account without a password or SMS code — effectively hijacking messages, contacts, and full account control. A click on a prepared link, placed in a group chat for example, was enough; no separate file execution or install was needed.

Telegram's local passcode lock (Settings → Privacy and Security → Passcode Lock) meaningfully reduces the risk: it encrypts session files on disk, so even a stolen tdata folder is useless for logging in without it.

What Telegram did

Telegram fixed the vulnerability in version 7.2.9 (September 17, 2026), removing the vulnerable interpret: handler and correcting how command separators are escaped in the IPC protocol. As of the write-up's publication (October 9, 2026) there were no confirmed cases of mass exploitation in the wild, but a working proof-of-concept was published alongside the technical details — meaning the risk for anyone still on an old build became practical, not just theoretical.

What this means for everyday users

If your computer runs Telegram Desktop 7.2.8 or earlier, updating to 7.2.9+ closes this exact flaw and should be step one. CVE-2026-107181 is another reminder of a broader pattern: messaging apps keep getting hit through IPC and link-handling features, not just attachments — we covered the related basics in our guide to protecting accounts from takeover.

It's also worth keeping not just your messenger but every installed app current — that's what closes vendor-known holes attackers actually use, something we detailed in our piece on the risks of unpatched devices.

How to protect yourself

  • Update Telegram Desktop to 7.2.9 or newer — the About/Help menu shows your current version.
  • Turn on Telegram's local passcode in privacy settings — it encrypts session files on disk.
  • Don't open tg:// links from unverified sources, even ones shared in a group you trust.
  • If you suspect compromise, check active sessions (Settings → Devices) and end any you don't recognize.

This specific flaw lives at the application level on your device, and no VPN patches it — only updating the client does. But on untrusted networks (cafés, airports, hotels) messenger traffic is still worth encrypting separately: the LiMP VPN app hides which services you use from the network owner or ISP, though it doesn't substitute for updating Telegram itself. Plans from 69 ₽/month, a verified no-logs policy: LiMP VPN pricing.

Sources