AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Before you orderOffer from Amazon

Get privacy and security gear delivered free with Prime

  • Fast, free delivery on millions of items
  • Prime Video, Amazon Music and more included
  • Member-only deals all year
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

Security researcher BeakSec reported a Telegram Desktop vulnerability that could let a victim who clicked a crafted link have local files read and sent to an attacker-controlled chat. The report says affected versions extended through 7.2.8 and that Telegram fixed the issue in 7.2.9; the claimed account takeover depended on obtaining files used for login.

Telegram Desktop versions through 7.2.8 contained a link-handling flaw that could allow an attacker to make a victim’s running app read a local file and send it to a chat, according to a technical report by BeakSec. The researcher says the vulnerability, listed as CVE-2026-107181, was fixed in version 7.2.9; exploiting it required the victim to click a crafted link.

BeakSec’s report describes a chain involving two defects in how Telegram Desktop processes links when the app is already open. The newly launched process forwards a link to the existing instance through a local socket, using a text format in which semicolons divide commands. According to the researcher, the link is not escaped before being placed in that format, allowing a semicolon inside a crafted link to be interpreted as the start of a separate command.

The injected command can reach Telegram’s internal interpret: URI handler. BeakSec says that handler reads an instruction file and can send a file named in that file to a specified chat, without checking who requested the action or asking the user to confirm. Combined with the command injection, the researcher reports that an attacker could trigger arbitrary local file read and exfiltration after a link click.

The report says the researcher confirmed the issue on Windows using Telegram Desktop 6.9.3, while listing versions through 7.2.8 as affected. It gives a CVSS 3.1 score of 8.1, High, and identifies 7.2.9 as the fixed release, citing commit db3405699f. BeakSec says files used for Telegram login could be targeted in a further account-takeover chain; that outcome depends on access to relevant files and is a claim in the report, not evidence that accounts were broadly compromised.

At a glance
reportWhen: Reported in 2026; fixed in Telegram Des…
The developmentBeakSec published details of a Telegram Desktop link-handling flaw, identified as CVE-2026-107181, that Telegram fixed in version 7.2.9.

How a Link Could Expose Files

The reported flaw matters because it connects a familiar action—clicking a link—to access to files stored on the victim’s computer. If the described behavior works as reported, the attacker would not need prior access to the account or a separate file-transfer action from the victim beyond opening the crafted link. The report lists network access as the attack vector, no privileges required, and user interaction required.

That risk is more serious than an unwanted link opening or the app closing. A file sent to a chat could contain private information or data used to access an account. BeakSec specifically describes a possible route to account takeover through login-related files, but does not establish how often those files would be present, whether every account was exposed, or whether attackers used the flaw in real-world campaigns.

encrypted USB flash drive

Amazon

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

The Desktop Link-Handling Chain

Telegram Desktop registers the tg: link scheme with the operating system. When a link is opened while the app is already running, the report says a second process passes the link to the existing instance through a local socket, then exits. The existing instance reconstructs commands from the text it receives, splitting them at semicolons.

BeakSec’s analysis says that process created the injection point: a semicolon included in a URL was treated as a command separator rather than as part of the URL. The researcher then traced the injected command to Telegram’s internal interpret: handler, which was used by Telegram’s release-publishing workflow to process instruction files. The report says the handler’s file-sending behavior lacked checks on who invoked it and did not require confirmation.

The article identifies 7.2.9 as the fix and cites a specific commit, but the supplied report does not provide a full vendor advisory or a detailed account of the patch. Its technical findings are a researcher’s published analysis; claims about broader exposure should be treated separately from the demonstrated code path.

“Together they turn a clicked link into arbitrary file read.”

— BeakSec, in the vulnerability report

Scope and Exploitation Evidence

The available source is BeakSec’s report. It documents a confirmed test on Windows with version 6.9.3 and describes versions through 7.2.8 as affected, but it does not show testing across every supported operating system or release. The report excerpt also does not establish whether the flaw was exploited outside the researcher’s testing, how many users may have been affected, or whether any user files or accounts were actually stolen.

It is also unclear from the supplied material what exact changes Telegram made in 7.2.9, whether the app displayed any warning in all relevant link-opening circumstances, and whether the company issued separate guidance to users. The claimed account-takeover path is conditional on an attacker obtaining login-related files and should not be read as confirmation that every affected account could be taken over.

Update to Version 7.2.9

Users of Telegram Desktop should check that they are running version 7.2.9 or later, the release BeakSec identifies as fixing the vulnerability. The report does not provide installation instructions or confirm the update status of every distribution channel, so users may need to check the version available through their usual Telegram download or software update route.

Further clarity would depend on a fuller vendor advisory or additional technical reporting, including details on the patch, platform coverage and any evidence of exploitation. Until then, the confirmed point in the supplied material is the researcher’s reported vulnerability and identified fixed version—not a verified tally of stolen files or compromised accounts.

Key Questions

What did the Telegram Desktop vulnerability allow?

According to BeakSec, a crafted link could exploit command parsing in a running Telegram Desktop instance and reach an internal handler that reads and sends a local file to a chat. The victim had to click the link.

Which versions were reported as affected?

BeakSec lists Telegram Desktop versions through 7.2.8 as affected. The report says testing confirmed the issue on Windows with version 6.9.3.

Has Telegram fixed the flaw?

The report identifies Telegram Desktop 7.2.9 as the fixed version and cites commit db3405699f. The supplied source does not include a separate Telegram advisory.

Were Telegram accounts confirmed stolen?

The report describes a possible account-takeover chain involving files used for login, but the supplied material does not confirm real-world account theft or widespread exploitation.

Source: hn

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Radicle: Disclosure Of Vulnerability In The Network Protocol

Radicle has publicly disclosed a security vulnerability affecting its network protocol, prompting investigation and response from the developer community.

CVE-2026-60137: WordPress Core SQL Injection Vulnerability Actively Exploited (CISA KEV)

A critical SQL injection vulnerability in WordPress core, CVE-2026-60137, is actively exploited, allowing unauthenticated attackers to compromise sites.

CVE-2026-48939: iCagenda Unrestricted Upload Of File With Dangerous Type Vulnerability Actively Exploited (CISA KEV)

A critical vulnerability in iCagenda allows unrestricted upload of malicious files, actively exploited and posing serious security risks.

Investigating three real-world incidents in our cybersecurity evaluations

Authorities are examining three recent cybersecurity incidents to assess vulnerabilities and response effectiveness, with findings pending.