· via Hacker News – Front Page (native)
Telegram Desktop one-click account takeover came from an unescaped semicolon in IPC
A BeakSec disclosure details how a crafted chat link let attackers exfiltrate arbitrary local files from Telegram Desktop users and hijack their sessions; fixed in version 7.2.9.

What happened
A technical write-up by security researchers at BeakSec describes a two-part flaw in Telegram Desktop that turned a single clicked chat link into a full account takeover. Tracked as CVE-2026-107181 and rated 8.1 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N), the chain let a remote attacker read arbitrary files from a victim's machine and have them delivered to an attacker-controlled chat. According to the post, versions through 7.2.8 were affected and the bug was confirmed on Windows; the fix shipped in version 7.2.9 under commit db3405699f.
The scenario BeakSec sketches is blunt: a victim is added to a Telegram group, a link appears in the chat, and clicking it hands the account to someone else, with Telegram's default download behavior quietly doing part of the work.
The injection
Telegram Desktop registers the tg:// URI scheme with the operating system. When a tg:// link is clicked and the app is not yet running, the new process handles the URL internally. But when an instance is already alive, the OS still launches a second process; that process detects the existing one over a local socket, hands it the link, and exits.
A socket carries bytes, not objects, so the link is serialized into text: each instruction is a keyword, an argument, and a terminating semicolon, as in OPEN:url;. The long-running instance splits the incoming stream at every semicolon and treats each fragment as a command in its own right.
The separator is never escaped. A URL containing a semicolon inside its query is one link as far as the client process is concerned, but the server-side split turns it into several commands — a textbook injection. By itself the injected command set looks harmless (it accepts only show and quit), but the OPEN: instruction rebuilds whatever follows it into a URL with no restriction on the scheme, and that is the opening.
An internal scheme with no guardrails
While reviewing the code, the researcher found a second URI scheme, interpret:, that is never registered with the operating system. It exists solely inside Telegram's own code and was built for publishing releases: a script wrote a small instruction file naming a destination channel, a file to attach, and a caption, then launched Telegram pointed at that file.
The function behind it, InterpretSendPath, reads the named file from disk and sends it to a chat with no confirmation prompt and no check on who requested the action. An optional from: line, meant to stop operators publishing a release from the wrong account, is validated only when present, so leaving it out skips the check. The destination, set by channel:, must be a channel or supergroup — which an attacker can supply.
Called from a local command line by a trusted operator, this was unremarkable. Made reachable through the socket injection via OPEN:interpret:..., a privileged file-send primitive became triggerable by a clicked link.
Getting the payload onto disk
The attacker still needs an instruction file on the victim's machine at a predictable path. BeakSec notes that Telegram Desktop, in its default configuration, automatically downloads files up to 8 MiB received in group chats into a standard folder, keeping the sender's chosen filename (automatic download is off for broadcast channels). Sending the instruction file as a group attachment therefore places it on disk without any action by the victim.
The crafted link then injects an instruction opening interpret: against that downloaded file, which points file: at anything worth stealing and channel: at the attacker's destination. The result is arbitrary local file read, exfiltrated to a chat the attacker controls. Aimed at the files that constitute the victim's login, it becomes account takeover.
Why it matters
- The root defect is an old one: serialized data crossing a trust boundary with an unescaped delimiter. Any application that passes structured commands through a local socket, pipe or command line needs escaping, not just splitting.
- The second defect is the more interesting lesson. Functionality that was safe in its original context — a release script on an operator's machine — became dangerous once another bug made it remotely reachable. Authorization checks should not depend on how a feature is invoked.
- Internal-only URI schemes are still attack surface even if the OS never sees them, and permissive URL handling (no scheme allowlist) is what connected the two flaws.
- Default auto-download in group chats materially lowered the bar, removing steps the victim would otherwise have to take.
- Practically, the advice is simple: update Telegram Desktop to 7.2.9 or later.
- #telegram
- #security
- #vulnerability
- #desktop
- #ipc