Pull to refresh
Logo
Telegram Desktop flaw let one crafted link take over an account

Telegram Desktop flaw let one crafted link take over an account

New Capabilities

An unescaped semicolon in Telegram's local socket turned a single click into full account theft

Today: Disclosure reaches broad public attention

Overview

Updated 1 hour ago

A single clicked link could empty a Telegram Desktop account. The link injected hidden commands into Telegram's local inter-process socket, and three files holding the user's login were read and uploaded to an attacker's chat. With those files, the attacker could sign in as the victim.

The bug joined two flaws. The socket never escaped the semicolon that separates commands, and an internal helper called `interpret:` read any file and sent it to a chat without confirmation. Telegram fixed it in version 7.2.9, shipped September 17, 2026, with no security advisory attached. The technical details became public in October.

Why it matters

Anyone running Telegram Desktop before 7.2.9 could lose their account to one link, and many Linux builds remain unpatched.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

8.1
CVSS 3.1 severity rating (High)
Rated High on the 1-10 common vulnerability scoring scale.
8.6
CVSS 4.0 severity rating (High)
VulnCheck's 4.0 score for the same flaw; NVD still lists it as awaiting analysis.
3
Files required for full account takeover
The session keys, the encryption key file, and the account data index.
83
Days from disclosure to fix
Reported June 25, fixed in commit db3405699f on September 16, 2026.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

June 2026 October 2026

7 events Latest: Today
Tap a bar to jump to that date
  1. Disclosure reaches broad public attention

    Today Disclosure

    The writeup and CVE details circulate widely, drawing attention to the silently shipped fix.

  2. CVE assigned

    Disclosure

    VulnCheck assigns CVE-2026-107181 and rates it 8.1 High under CVSS 3.1 and 8.6 under CVSS 4.0.

  3. Technical writeup published

    Disclosure

    beaksec publishes the full attack chain showing how one clicked link reads session files and hands over the account.

  4. ZDI closes the case

    Disclosure

    ZDI marks the report as already fixed by the vendor and returns disclosure rights to the researcher.

  5. Telegram Desktop 7.2.9 ships

    Release

    The patched version publishes, but the changelog lists only a rendering fix and no security advisory accompanies it.

  6. Telegram patches the bug

    Fix

    Commit db3405699f removes the `interpret:` helper and escapes the semicolon separator in the single-instance socket.

  7. Flaw reported through ZDI

    Disclosure

    An independent researcher reports the IPC injection vulnerability in Telegram Desktop to Trend Micro's program.

Scenarios

1

Unpatched Telegram installs targeted in the wild

Possible Resolves by Apr 10, 2027

Discussed by: CISA's KEV process and threat intel firms such as VulnCheck

Linux and older Windows builds still run vulnerable versions, and the technical writeup is now public. If attackers chain it into campaigns, CISA would add the CVE to its Known Exploited Vulnerabilities catalog, the clearest signal of in-the-wild use. No network indicators were published at disclosure, so exploitation would start from scratch.

2

Researchers find a sibling IPC flaw in another desktop app

Possible Resolves by Oct 10, 2027

Discussed by: Independent security researchers; the pattern is common to single-instance bridges

The unescaped-separator bug is a general design smell in apps that hand links to a running instance over a local socket. The Telegram writeup gives researchers a template to audit similar clients. A new CVE describing the same mechanism in another major app would confirm the pattern is broader than Telegram.

3

Patch adoption lags and accounts stay exposed

Uncertain Resolves by Jan 15, 2027

Discussed by: Tenable's Linux unpatched advisories and silent-update watchers

The fix shipped with no advisory, so many users may not know to update. Tenable already lists CVE-2026-107181 as unpatched on some Linux distributions. If most desktop installs run version 7.2.8 or older well into 2027, the vulnerability remains live even though it is patched upstream.

Historical Context

2 moments from history that rhyme with this story — and how they unfolded.

May 2019

WhatsApp spyware call (2019)

A flaw in WhatsApp's voice-call handling let NSO Group's Pegasus spyware install on a phone with a single call, needing no action from the target beyond accepting it. The bug was tracked as CVE-2019-3568.

Then

WhatsApp urged all users to update and disclosed the bug publicly within days.

Now

The case showed messaging apps as prime entry points for spyware and led to lawsuits against NSO Group.

Why this matters now

Like the Telegram flaw, a single interaction inside a trusted messaging app was enough to compromise a target's device and data.

August 2016

Trident iPhone attack chain (2016)

Three iOS vulnerabilities chained through a malicious link sent in a message installed Pegasus spyware with no user action. Citizen Lab discovered the chain while investigating an activist's phone.

Then

Apple shipped iOS 9.3.5 within days to patch all three flaws.

Now

The discovery publicized commercial zero-day spyware and pushed Apple toward faster emergency patches.

Why this matters now

A single link delivered through a messaging app gave full device compromise, the same one-click threshold the Telegram vulnerability crossed.

Sources

(6)