AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Before you orderOffer from Amazon

Get privacy and security gear delivered free with Prime

  • Fast, free delivery on millions of items
  • Prime Video, Amazon Music and more included
  • Member-only deals all year
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

Security researcher beaksec reported that a crafted link clicked in Telegram Desktop could exploit command parsing and an internal URI handler to read a local file and send it to a chat. The report says versions through 7.2.8 were affected and Telegram fixed the issue in 7.2.9; the account takeover impact was demonstrated by targeting files used for login.

Security researcher beaksec reported a vulnerability in Telegram Desktop that could let a crafted link trigger unauthorized local file access and send a file to an attacker-controlled chat. The report says versions through 7.2.8 were affected and identifies 7.2.9 as the fixed release; it describes a chain involving unsafe command parsing and an internal URI handler.

According to beaksec’s technical report, the issue arises when Telegram Desktop is already running and receives a link. The newly launched process passes the link to the existing instance through a local socket, converting it into a text command. Telegram’s command format uses semicolons to separate instructions, but the report says the link’s contents were not escaped to protect that separator. A semicolon inside a crafted link could therefore be interpreted as the start of another command.

The injection alone was not enough to read files. The researcher says the injected command could reach Telegram’s internal interpret: URI handler, which processes a text instruction file containing a file path and a destination chat. The report alleges that this handler did not verify who had requested the operation or ask the user to confirm it. In combination, the flaws could make Telegram read a specified local file and send it through the app.

Beaksec says the chain was used to target files involved in Telegram login, creating a route to account takeover. The report lists CVE-2026-107181, a CVSS 3.1 score of 8.1, and a fix in version 7.2.9 at commit db3405699f. It says the vulnerability was confirmed on Windows using version 6.9.3. Those scope and impact details come from the researcher’s report; the material provided does not include an independent validation or a statement from Telegram.

At a glance
reportWhen: Reported in 2026; the cited fix is Tele…
The developmentA security researcher disclosed a Telegram Desktop vulnerability chain that could expose local files through a clicked link, and reported that version 7.2.9 fixes it.

How a Link Could Expose Files

The reported chain matters because it connects an ordinary user action—clicking a link—to an operation that can read and transmit a local file. If the described behavior is accurate, files stored on a device could be exposed without the user separately choosing them for upload. The researcher’s account takeover demonstration also points to a risk beyond the loss of a single document: files used to authenticate an account may help an attacker gain access to that account.

The report describes the flaw as requiring user interaction, reflected in its CVSS vector, which lists network access, low complexity and no privileges, but user interaction is required. That distinction matters: this is not described as an attack that happens merely because Telegram is installed or running. A user must click a malicious link, and the stated affected product is Telegram Desktop. The report does not establish how often the vulnerability was exploited or whether any users were affected in real-world attacks.

The incident also highlights the security boundary between links and application internals. Telegram’s desktop client accepted links, relayed them between processes and interpreted an internal command format. According to the researcher, failing to preserve the boundary between link data and command separators allowed untrusted input to reach a file-sending feature. The practical concern is therefore both the reported defect and the need for users to update to the version identified as fixed.

Amazon

Telegram Desktop security software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

From Link Handoff to File Sending

Telegram registers the tg: scheme so operating systems can open Telegram links in its desktop application. Beaksec explains that, when the app is already running, a second process passes the link to the existing process over a local socket and exits. The receiving process reconstructs instructions from text sent over that socket.

The report says the instructions use a keyword, an argument and a semicolon delimiter. A link containing a semicolon could cross that boundary as text and be split into multiple commands by the receiving process. One accepted command, OPEN:, could then pass a URL to Telegram’s internal handlers, including the interpret: scheme.

Beaksec says interpret: was used in Telegram’s release workflow to read instruction files specifying a channel, a file to send and accompanying text. The researcher’s account is that the same functionality was reachable from a crafted link, but without the checks or confirmation expected for a user-requested file transfer. The report names versions through 7.2.8 as affected and 7.2.9 as fixed.

“A crafted link does not arrive as one instruction: it arrives as several.”

— Beaksec, security researcher

Amazon

local file encryption tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Scope and Exploitation Still Unclear

The available source material is a researcher’s technical report. It does not include a response from Telegram, independent reproduction by another security team, or details about whether the vulnerability was exploited outside testing. The report says it was confirmed on Windows with version 6.9.3, while listing Telegram Desktop through 7.2.8 as affected; it does not provide platform-by-platform confirmation for every listed version.

It is also unclear how many users may have been exposed, whether attackers attempted to use the flaw, or what specific protections might limit access to files on different operating systems. The report identifies 7.2.9 as the fix but the supplied material does not describe the full patch or provide a vendor advisory confirming the affected range. Users should treat the technical details and impact as attributed findings until further confirmation is available.

Amazon

VPN for secure messaging

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Update to the Reported Fixed Release

Beaksec identifies Telegram Desktop 7.2.9 as the version that fixes the vulnerability. Users of the desktop app should check their installed version and update through Telegram’s official distribution channel if they are using an earlier release. The report does not say whether additional remediation is needed for users who may have clicked a suspicious link.

Further clarity would come from a Telegram security advisory confirming the affected versions, supported operating systems and patch details, as well as any information about exploitation in the wild. Until then, the known status is that the researcher reported the flaw and named a fixed version; the extent of any real-world exposure remains unknown.

Amazon

antivirus software for Windows

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What did the Telegram Desktop vulnerability allow?

According to beaksec, a crafted link could exploit command parsing and Telegram’s internal interpret: handler to read a local file and send it to a chat. The researcher also said files involved in account login could be targeted.

Which Telegram Desktop versions were affected?

The report lists Telegram Desktop versions through 7.2.8 as affected and says the issue was fixed in 7.2.9. It specifically says the behavior was confirmed on Windows using version 6.9.3.

Yes. The report describes a malicious link being clicked in Telegram Desktop. It does not describe a no-click attack.

Has Telegram confirmed the vulnerability or any real-world attacks?

The supplied source is beaksec’s technical report and does not include a Telegram statement or evidence that the flaw was exploited in real-world attacks. Those points remain unconfirmed in the available material.

Source: hn

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

CVE-2026-60004: Gitea Code Injection Vulnerability Actively Exploited (CISA KEV)

A critical code injection vulnerability in Gitea, CVE-2026-60004, is being actively exploited. CISA has added it to KEV, raising security concerns.

WordPress: Unauthenticated Path Traversal Leading To Conditional RCE

Security researchers have identified a vulnerability in WordPress allowing unauthenticated path traversal that could lead to conditional remote code execution.

Flawed Routers Flood University Of Wisconsin Internet Time Server (2003)

In 2003, flawed routers caused a flood of traffic to the University of Wisconsin’s internet time server, raising concerns about network security and device reliability.