⏱️ Reading time: 10 min
A single click on a link inside a group chat was enough for an attacker to read any file on the victim’s machine and, with it, steal the active session of their account. The finding, published by the researcher behind the beaksec blog and catalogued as CVE-2026-107181, describes the Telegram Desktop vulnerability that turned an ordinary link into a key for taking over an account.
📑 En este artículo
- TL;DR
- What Telegram Desktop Is
- What Happened With the Telegram Desktop Vulnerability
- Context and History
- Technical Details
- Impact and Analysis
- What’s Next
- Frequently Asked Questions
- What makes Telegram Desktop vulnerable to this attack?
- Do I need to do anything if I already updated to version 7.2.9?
- Does the IPC flaw also affect the Telegram mobile app?
- What is the interpret: scheme that the flaw exploits?
- How do I know if my copy of Telegram Desktop is patched?
- What could an attacker steal with this exploit?
- References
The flaw combined two bugs that on their own weren’t worth much: an injection in the internal channel the client uses to talk to itself, and a command inherited from Telegram’s publishing tools that never asked for confirmation. Together, they were enough to exfiltrate the session files without the victim noticing anything unusual.
TL;DR
- Telegram Desktop patched CVE-2026-107181: a click on a link stole the account’s session.
- The flaw chained a command injection in the IPC socket with the internal interpret: scheme.
- Affected versions go up to 7.2.8, confirmed in Windows build 6.9.3.
- CVSS 3.1 rated the flaw at severity 8.1 (high), with no impact on availability.
- The fix arrived in version 7.2.9 with commit db3405699f.
What Telegram Desktop Is
Telegram Desktop is Telegram’s official desktop client for Windows, macOS, and Linux, developed by Telegram FZ-LLC. It syncs chats and sessions with the app’s cloud and exposes a tg:// link scheme to open commands from the operating system, the exact channel where the Telegram Desktop vulnerability appeared.
What Happened With the Telegram Desktop Vulnerability
The technical report, written by the researcher who publishes under the pseudonym beaksec, documents the flaw through version 7.2.8 of Telegram Desktop and confirms it in Windows build 6.9.3. CVE-2026-107181 received a score of 8.1 out of 10 on CVSS 3.1, with the vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N: remote attack, low complexity, no prior privileges required, but mandatory user interaction, the click on the link.
Telegram fixed the issue in version 7.2.9, identified in the project’s repository with commit db3405699f. The report followed the usual responsible disclosure process: the researcher gave notice before publishing the technical details, and the blog post went out once the fix was already available to all users.
The starting point of the problem isn’t in Telegram’s encryption or servers, but in how two processes of the same program talk to each other on the victim’s computer. That’s where the chain begins.
Context and History
When a user clicks a tg:// link, the operating system doesn’t know whether Telegram Desktop is already open: it launches a new process regardless. That new process tries to connect to a local socket; if it succeeds, that means an active instance already exists, so it hands over the link and closes. That inter-process communication (IPC) uses its own simple format: a keyword, its argument, and a semicolon that closes the instruction.
Within that same internal channel lives interpret:, a scheme the operating system doesn’t recognize as a protocol (it isn’t registered with any external handler) but that Telegram’s own code knows how to interpret on the fly, just like any other startup link. interpret: was born as an internal tool: when the team published a new version, a script would put together a text file with the target channel and the file to send, then launch Telegram Desktop pointing at that file. The client would read the instruction and upload the build with its changelog to the official channel, without anyone having to drag the file in by hand.
The instruction file accepts a from: field that compares the logged-in account’s id against the expected id, meant to prevent an operator from publishing a release from the wrong account. But that comparison only runs if the from: line is present: omitting it skips it entirely. The destination, controlled by the channel: field, only requires it to be a real channel or supergroup.
| Scenario | Who triggers it | Result |
|---|---|---|
| Original use of interpret: | An internal script with the instruction file already on the operator’s disk | Publishes the new build and changelog to Telegram’s official channel |
| Malicious use via IPC injection | Any sender who manages to sneak a second command into the link | Reads a local file and sends it to a chat the victim doesn’t control, without asking for confirmation |
Technical Details
The serialization format used by Telegram Desktop’s IPC doesn’t escape the semicolon when that character appears inside the argument itself. A normal link turns into a single instruction, something conceptually like this:
OPEN:tg://resolve?domain=channel;
But if the URL received by the new process already carries a semicolon in one of its query parameters, that process still treats it as a single string (to it, the semicolon is just one more character inside the URL) and forwards it as-is through the socket. The active instance, however, doesn’t make that distinction: it splits the received string at every semicolon and treats each fragment as an independent command. A URL with one extra semicolon turns, on the other side, into two instructions:
OPEN:tg://resolve?domain=channel;CMD:show;
That’s the injection, the first flaw in the chain. The second flaw is where the injected instruction can point: the internal protocol recognizes four commands total, and three are harmless (among them CMD:, which only accepts show and quit, so the worst it can do is close the window). The fourth is OPEN:, and that’s where the real detail lies: it accepts any URL, without filtering the scheme. Through it, interpret: is reachable, the scheme that reads an instruction file from disk and sends the file that file names, without verifying who requested it or showing a confirmation dialog.
The following diagram summarizes the full path, from the victim’s click to the file leak:
sequenceDiagram
participant V as Victim
participant N as New process
participant A as Active instance
participant T as Attacker's chat
V->>N: clicks the malicious link
N->>A: connects to the local socket and forwards the combined command
A->>A: splits the received string at each separator
A->>T: interpret reads the file and sends it without confirmation
Note over A,T: the victim sees no alert
There’s no direct way to verify this specific behavior from outside the process: the injection happens entirely in memory, inside the local socket, and leaves no record visible to the end user. That’s why the only effective control is the installed client version, not a signal that can be observed during the attack.
💭 Key takeaway: In plain terms, the vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N says: network attack, no extra complexity, no prior privileges, with a click from the victim, high confidentiality and integrity impact, and zero impact on availability.
Impact and Analysis
The real impact of the Telegram Desktop vulnerability isn’t that an attacker can read just any file, but which one: the session files that Telegram Desktop stores locally allow an active session to be reconstructed without going through phone verification again. Whoever manages to get those files sent to their own chat can operate the victim’s account as if they were the owner, without asking for a password or a code.
The chain requires human interaction (the click on the link), which is why the CVSS vector marks UI:R instead of a silent zero-click attack. But Telegram’s typical context, large groups where any member can drop a link, makes that single click easy to get: it doesn’t take sophisticated social engineering, it’s enough for the link to look like any other Telegram link.
The report confirms the behavior in Windows build 6.9.3. The IPC code that makes it possible (the single-instance socket, the serialization format, and the interpret: scheme) lives in the shared codebase of tdesktop, so there’s no technical reason to assume macOS and Linux were out of scope; the researcher simply documented and confirmed the case on one operating system.
A real limitation of the fix: patching the semicolon escaping and adding a confirmation to interpret: fixes this specific chain, but doesn’t audit the rest of the internal protocol. If another command shows up with the same pattern, without escaping separators or without asking for confirmation, the same type of chain becomes possible again.
What’s Next
Telegram already fixed the flaw in version 7.2.9, so the immediate recommendation is simple: update the desktop client. On Windows, macOS, or Linux, open Settings → Telegram Desktop and check the version shown at the bottom of that screen: it should read 7.2.9 or higher. If it still reads 7.2.8 or earlier, that client remains exposed to the Telegram Desktop vulnerability until you update it.
The report doesn’t mention active exploitation before publication, which is expected in responsible disclosure: the fix comes out first, the technical details after. There’s also, for now, no separate official advisory from Telegram beyond the change in the changelog on the project’s releases page.
What remains pending, though, is a broader audit of Telegram Desktop’s internal protocol: if interpret: had been hiding this problem for years (it was born as a tool for a publishing script, not as a surface exposed to external links), it’s not ruled out that other commands on the same channel deserve a similar review.
Try it yourself: open Telegram Desktop, go to Settings, and confirm the version reads 7.2.9 or higher before opening links from chats you don’t control again.
Frequently Asked Questions
What makes Telegram Desktop vulnerable to this attack?
The combination of an inter-process communication format that doesn’t escape the semicolon and an internal command, OPEN:, that accepts any URL without filtering the scheme, including the private interpret: scheme.
Do I need to do anything if I already updated to version 7.2.9?
No. Version 7.2.9 includes the fix from commit db3405699f and closes the injection chain described in CVE-2026-107181.
Does the IPC flaw also affect the Telegram mobile app?
The report confirms the issue in Telegram Desktop for Windows, the client that uses the tg:// scheme and the IPC socket described. It doesn’t cover Telegram’s mobile apps, which don’t share that single-instance socket mechanism.
What is the interpret: scheme that the flaw exploits?
It’s an internal link scheme, not registered with the operating system, that Telegram Desktop used to publish its own versions: it reads a local instruction file and sends the file that file names to a channel, without asking for confirmation.
How do I know if my copy of Telegram Desktop is patched?
Open Settings → Telegram Desktop and check the version number: 7.2.9 or higher already includes the fix for this flaw.
What could an attacker steal with this exploit?
Telegram Desktop’s local session files, enough to take control of an account without needing the phone’s verification code again.
References
- beaksec: Telegram Desktop, one-click account takeover via IPC injection: the original technical report with the full analysis of the exploitation chain.
- NVD: CVE-2026-107181: the official vulnerability entry, with the CVSS 3.1 vector and severity 8.1.
- GitHub: telegramdesktop/tdesktop: the client’s official repository, where the IPC code and the fix commit live.
- GitHub: tdesktop releases: the changelog listing version 7.2.9 with the fix for the flaw.
📱 Enjoy this content? Follow @programacion on Telegram for daily tech content in Spanish: quick summaries, fresh content every day.
Featured image: Foto de Moritz Kindler en Unsplash
Did it work for you? Got a different error? Say so below: questions get answered and help the next reader.
Leave a comment
0 Comments