Security researchers have published working proof-of-concept code for a Telegram Desktop vulnerability that could let an attacker steal a victim’s local session data and take over their account after nothing more than a single click on a malicious link. The flaw, now tracked as CVE-2026-107181, carries a CVSS 4.0 score of 8.6, placing it firmly in high-severity territory.
How a Link Clicked Outside Telegram Becomes a Takeover
The bug lives in how Telegram Desktop handles links that are opened from outside the application itself, such as from a web browser. When Telegram is already running, a second instance hands the clicked link over to the active one through a local inter-process communication (IPC) channel. Researcher Beaksec, who published the technical write-up in early October and updated it days later, found that this channel failed to properly escape a character used to separate internal records.
That oversight, classified under CWE-143 for improper handling of record delimiters, means an attacker can smuggle an extra command inside what looks like an ordinary link. Telegram’s IPC parser ends up treating part of the malicious link as a legitimate internal instruction rather than harmless data.
An Old Helper Function Left the Door Open
According to the published analysis, the injected command can reach an outdated internal helper that was originally built for release publishing. That helper was never designed with untrusted input in mind. It can read arbitrary local files, including Telegram’s own session data, and forward them into a chat window without any permission prompt or confirmation dialog from the user.
Once session files are exfiltrated this way, an attacker can potentially reuse them to log in as the victim elsewhere, effectively hijacking the account without ever needing a password. The researcher demonstrated the full chain on Windows using Telegram Desktop 6.9.3 and confirmed the weakness persisted through version 7.2.8.
What “One-Click” Actually Requires
The one-click framing comes with real caveats worth noting before anyone panics. The malicious link has to be opened from outside Telegram, such as a browser, because links clicked from inside a chat follow a separate, unaffected code path. Most browsers also prompt the user before handing a link off to a desktop application, adding a small speed bump. The demonstrated exploit chain additionally relies on automatic group-file downloads being enabled and on settings that allow strangers to add a target to a group, meaning the practical blast radius depends heavily on a user’s default configuration.
So far there is no evidence this has been exploited in the wild, and the flaw does not appear on CISA’s Known Exploited Vulnerabilities list as of this writing. The proof-of-concept demonstrates feasibility, not an active campaign — but published, working exploit code tends to shrink that gap quickly.
A Quiet Fix With No Public Advisory
Telegram actually closed the hole weeks before the research went public. The company shipped the fix in a commit on September 16 and released version 7.2.9 the following day. The patch removes the legacy publishing helper entirely, properly escapes the record-separator character, and tightens handling of mixed record types in the IPC channel.
Notably, Telegram’s own release notes for 7.2.9 mention only a rendering fix and make no reference to a security issue. No dedicated security advisory for CVE-2026-107181 has surfaced from the vendor, which means organizations tracking patch status by changelog alone could easily miss that this update matters.
- Update immediately to Telegram Desktop 7.2.9 or later on every managed Windows endpoint.
- Enable a local passcode inside Telegram, which adds a layer of protection even if session data is somehow accessed.
- Restrict who can add you to groups and disable automatic downloads of files shared in chats and groups.
- Treat unexpected browser prompts asking to open Telegram with extra suspicion, especially from unfamiliar links.
The Takeaway for Defenders
This case is a reminder that changelog entries are not a substitute for a real vulnerability feed. A fix can ship quietly, long before researchers attach a CVE number and a severity score to it, leaving a window where patched-but-unaware organizations assume they’re still exposed, or worse, unpatched organizations assume a “rendering fix” doesn’t need urgent attention. Security teams should confirm desktop messaging clients are running current builds as a matter of routine, independent of whether a given release note mentions security at all, and should watch for any unexpected chat uploads or unfamiliar active sessions as a sign of possible prior exploitation.
Leave a Reply
You must be logged in to post a comment.