A recently disclosed vulnerability in Telegram Desktop could enable attackers to access local files and take over user accounts with a single click on a specially crafted external link. This flaw, identified as CVE-2026-107181, impacts versions prior to 7.2.9 and has been given a high severity rating of 8.6 on the CVSS 4.0 scale.
Details of the Vulnerability
Security researcher Beaksec published an analysis on October 3, 2026, detailing how the flaw allows attackers to access Telegram’s local session data. This potential breach occurs when users have not set a local passcode, enabling account takeover. The vulnerability arises from Telegram Desktop’s handling of links opened outside the application, leveraging inter-process communication (IPC) to pass such links to the app.
The flaw stems from the failure to properly escape a character that separates records in the IPC channel, allowing a malicious link to be interpreted as a command. This issue is classified as CWE-143, which refers to improper handling of record delimiters.
Impact and Exploitation
According to findings by ThreatWire, the exploit uses an outdated internal helper tool to read local files and send them through Telegram without user consent. This results in unauthorized access to a user’s session files, potentially allowing attackers to hijack the account. Although similar to previous methods of account takeover via voicemail, this vulnerability specifically targets the Desktop version.
The proof-of-concept was demonstrated on Windows using Telegram Desktop 6.9.3, with the flaw persisting through version 7.2.8. The research does not extend to macOS or Linux, and the vulnerability necessitates that the link be opened outside Telegram, such as from a web browser.
Mitigation and Recommendations
Telegram addressed the issue with a code update on September 16, followed by the release of version 7.2.9 on September 17. The update removes the legacy helper, escapes the record separator, and improves handling of mixed record types. The release notes only mention a rendering fix, omitting the security vulnerability.
Users are advised to immediately update Telegram Desktop to version 7.2.9 or later to protect against this exploit. In the interim, users should restrict group invitations, disable automatic downloads, and enable local passcodes. Caution is also advised when responding to browser prompts to open Telegram.
As of October 9, there have been no confirmed exploitations or CISA KEV listings related to this vulnerability. While a public proof-of-concept exists, it serves only to demonstrate the vulnerability’s potential, not confirmed attacks. Users who suspect they’ve been compromised should terminate other active sessions and review their chat history for suspicious file uploads.
