Security & privacy

Telegram Desktop account takeover via unescaped IPC injection

A critical vulnerability in Telegram Desktop allows attackers to steal session files and take over accounts through a single clicked link due to improper input escaping.

Illustration of a broken connection between a Telegram link and a secure lock
Illustration generated for this article

A security researcher has disclosed a high-severity vulnerability in Telegram Desktop that allows an attacker to take over a user’s account with a single click. The flaw, tracked as CVE-2026-107181, exploits how the application handles inter-process communication on Windows systems. By sending a crafted link through a group chat, an adversary can read arbitrary local files, including sensitive session data, without triggering any confirmation dialogs.

What happened

The vulnerability affects Telegram Desktop versions up to 7.2.8, with confirmed testing on version 6.9.3 for Windows. The issue was reported through the Zero Day Initiative (ZDI) on June 25, 2026. Telegram addressed the problem independently on September 16, 2026, via commit db3405699f, and released the fix in version 7.2.9 the following morning. The ZDI case was closed on September 30, 2026, after confirming the fix, and the CVE identifier was assigned on October 7, 2026.

The exploit chain begins when a victim is added to a Telegram group controlled by an attacker. The attacker posts a specially crafted link in the chat. When the victim clicks this link, the operating system launches a new Telegram process. This new process detects that an instance is already running and attempts to forward the URL to the existing instance via a local socket. Because the application fails to properly escape semicolons in the transmitted data, the URL is split into multiple commands. These injected commands trigger an internal feature that reads specific files from the disk and uploads them to the attacker’s group. The attacker then reconstructs the victim’s session data from these files to gain full account access.

How it works

Telegram Desktop registers the tg URI scheme with the operating system. When a user clicks a tg:// link, the OS launches the application. If Telegram is not running, the new process handles the link directly. However, if an instance is already active, the OS still launches a second process. This redundant process connects to a local socket listened to by the primary instance and serializes the URL into a text string to pass it over. The primary instance then deserializes this text to reconstruct the command.

The core failure lies in this serialization process. Telegram uses a custom format where instructions are separated by semicolons. The application does not escape semicolons found within the URL data before sending it over the socket. An attacker can embed semicolons in the link to inject additional commands. One of these injected commands utilizes the interpret: URI scheme, an internal mechanism designed to read a file specified in an instruction file and send it to a chat. This mechanism lacks checks for who initiated the request and does not prompt the user for confirmation, allowing silent exfiltration of critical files like the tdata folder contents.

Key details

  • Vulnerability ID: CVE-2026-107181 with a CVSS score of 8.1 (High).
  • Affected Versions: Telegram Desktop 7.2.8 and earlier, confirmed on Windows 6.9.3.
  • Fixed Version: Telegram Desktop 7.2.9, released on September 17, 2026.
  • Attack Vector: Remote, requiring user interaction (clicking a link) but no further privileges.
  • Impact: Arbitrary local file read leading to complete account takeover.
  • Root Cause: Unescaped semicolons in inter-process communication allowing command injection.

Why it matters

This incident highlights the risks inherent in inter-process communication (IPC) mechanisms, particularly when data crosses trust boundaries without rigorous sanitization. For developers building desktop applications, it serves as a reminder that serialization and deserialization are critical attack surfaces. Even simple text-based protocols can be vulnerable to injection attacks if special characters are not escaped correctly. The fact that the fix was shipped quietly, with the changelog only mentioning a rendering fix, underscores the importance of proactive patch management rather than relying on vendor advisories for critical security updates.

For users and IT leads, the impact is severe because it bypasses traditional security expectations. No password is phished, and no malware is installed in the traditional sense. The application itself performs the malicious action under the guise of normal operation. This means that endpoint protection tools may not flag the activity, as it originates from a trusted, signed binary. Understanding that local file access can be triggered remotely via UI interactions changes how we assess risk in desktop environments.

What you can do

  • Upgrade immediately: Install Telegram Desktop version 7.2.9 or later, which removes the vulnerable interpret: scheme and fixes the escaping issue.
  • Enable download prompts: Turn on the "ask where to save each file" setting to prevent automatic downloads of malicious instruction files.
  • Restrict group additions: Limit who can add you to groups to contacts only, reducing the chance of encountering attacker-controlled chats.
  • Set a local passcode: Configure a strong local passcode in Telegram settings. While this does not prevent file theft, it renders stolen session files unusable without the code.
  • Monitor for updates: Keep an eye on official release channels for security patches, even if they are not explicitly labeled as security fixes in the changelog.

Tools from the Bytechap store

Keep reading

All stories