Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Exploit in Telegram Desktop Allows Account Takeover

New Exploit in Telegram Desktop Allows Account Takeover

Posted on October 9, 2026 By CWS

A recently disclosed vulnerability in Telegram Desktop could enable attackers to access local files and take over user accounts with a single click on a specially crafted external link. This flaw, identified as CVE-2026-107181, impacts versions prior to 7.2.9 and has been given a high severity rating of 8.6 on the CVSS 4.0 scale.

Details of the Vulnerability

Security researcher Beaksec published an analysis on October 3, 2026, detailing how the flaw allows attackers to access Telegram’s local session data. This potential breach occurs when users have not set a local passcode, enabling account takeover. The vulnerability arises from Telegram Desktop’s handling of links opened outside the application, leveraging inter-process communication (IPC) to pass such links to the app.

The flaw stems from the failure to properly escape a character that separates records in the IPC channel, allowing a malicious link to be interpreted as a command. This issue is classified as CWE-143, which refers to improper handling of record delimiters.

Impact and Exploitation

According to findings by ThreatWire, the exploit uses an outdated internal helper tool to read local files and send them through Telegram without user consent. This results in unauthorized access to a user’s session files, potentially allowing attackers to hijack the account. Although similar to previous methods of account takeover via voicemail, this vulnerability specifically targets the Desktop version.

The proof-of-concept was demonstrated on Windows using Telegram Desktop 6.9.3, with the flaw persisting through version 7.2.8. The research does not extend to macOS or Linux, and the vulnerability necessitates that the link be opened outside Telegram, such as from a web browser.

Mitigation and Recommendations

Telegram addressed the issue with a code update on September 16, followed by the release of version 7.2.9 on September 17. The update removes the legacy helper, escapes the record separator, and improves handling of mixed record types. The release notes only mention a rendering fix, omitting the security vulnerability.

Users are advised to immediately update Telegram Desktop to version 7.2.9 or later to protect against this exploit. In the interim, users should restrict group invitations, disable automatic downloads, and enable local passcodes. Caution is also advised when responding to browser prompts to open Telegram.

As of October 9, there have been no confirmed exploitations or CISA KEV listings related to this vulnerability. While a public proof-of-concept exists, it serves only to demonstrate the vulnerability’s potential, not confirmed attacks. Users who suspect they’ve been compromised should terminate other active sessions and review their chat history for suspicious file uploads.

Cyber Security News Tags:account takeover, CVE-2026-107181, Exploit, IPC, local files, PoC, security flaw, security update, Software Security, Telegram, threat analysis, Vulnerability

Post navigation

Previous Post: AI Involvement in South Korean Bank Hacks Raises Concerns
Next Post: Federal Agencies Urged to Patch Flaws Exploited by Flax Typhoon

Related Posts

Critical AdonisJS Vulnerability Allow Remote Attacker to Write Files On Server Critical AdonisJS Vulnerability Allow Remote Attacker to Write Files On Server Cyber Security News
Researchers Evaded Elastic EDR’s Call Stack Signatures by Exploiting Call Gadgets Researchers Evaded Elastic EDR’s Call Stack Signatures by Exploiting Call Gadgets Cyber Security News
Exploit Code Published for Microsoft SCCM Vulnerability Exploit Code Published for Microsoft SCCM Vulnerability Cyber Security News
Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome Cyber Security News
Cerberus Stalkerware Exploits Google Play with Firebase Cerberus Stalkerware Exploits Google Play with Firebase Cyber Security News
Lumma Infostealer Malware Attacks Users to Steal Browser Cookies, Cryptocurrency Wallets and VPN/RDP Accounts Lumma Infostealer Malware Attacks Users to Steal Browser Cookies, Cryptocurrency Wallets and VPN/RDP Accounts Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Container Image Scanning Tools of 2026
  • Google Domains Expose Vulnerability in Recent ccTLD Hijacks
  • Federal Agencies Urged to Patch Flaws Exploited by Flax Typhoon
  • New Exploit in Telegram Desktop Allows Account Takeover
  • AI Involvement in South Korean Bank Hacks Raises Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Container Image Scanning Tools of 2026
  • Google Domains Expose Vulnerability in Recent ccTLD Hijacks
  • Federal Agencies Urged to Patch Flaws Exploited by Flax Typhoon
  • New Exploit in Telegram Desktop Allows Account Takeover
  • AI Involvement in South Korean Bank Hacks Raises Concerns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark