A newly published proof of concept (PoC) has demonstrated a security flaw in Telegram Desktop that could allow attackers to steal local files and potentially take over a user’s account.
The vulnerability is tracked as CVE-2026-107181 and affects Telegram Desktop versions before 7.2.9. It has a CVSS 4.0 score of 8.6 (High).
Security researcher Beaksec published details of the vulnerability on October 3, 2026, with an update on October 7. VulnCheck assigned the CVE shortly afterward.
The attack relies on a specially crafted link. If the victim clicks the link from outside Telegram while the desktop application is already running, the attacker may be able to interact with Telegram’s local session data.
How the Telegram Desktop Flaw Works
The problem is related to the way Telegram Desktop processes links opened from other applications.
When Telegram is already running, a newly opened link is passed to the existing Telegram process through a local communication mechanism called inter-process communication (IPC).
The vulnerability occurs because Telegram did not properly handle a special character used to separate commands or records within this communication process.
An attacker could place the character inside a specially crafted link. Telegram could then interpret part of the link as an additional command instead of treating the entire content as normal link data.
The issue has been classified as CWE-143, which covers improper handling of record delimiters.
File Theft Could Lead to Account Takeover
The public PoC shows how the flaw could be combined with an older internal Telegram component.
According to the research, the injected command could reach a legacy helper that was originally designed for publishing releases. The component could access local files and send them through Telegram without requiring normal permission checks or confirmation from the user.
This creates a serious risk because Telegram stores local session information on the device.
If an attacker obtains the right session data, they may be able to reuse the victim’s existing Telegram login and gain access to the account.
The researchers demonstrated the attack on Windows using Telegram Desktop 6.9.3 and reported that the issue remained in versions through 7.2.8.
The attack also has some limitations:
- The malicious link needs to be opened outside Telegram.
- Links opened inside Telegram use a different processing path.
- The attack was demonstrated on Windows; the available research does not show the same attack on macOS or Linux.
- Certain automatic download and group-invitation settings can affect the attack chain.
- A browser may display a warning before opening Telegram Desktop.
These conditions are important when assessing the actual risk rather than assuming every Telegram user is automatically vulnerable.
Telegram Releases a Fix
Telegram addressed the vulnerability in September 2026.
The company fixed the issue in a development commit on September 16 and released Telegram Desktop 7.2.9 on September 17.
The changes include removing the vulnerable legacy helper, properly handling the record-separator character, and improving how different types of local messages are processed.
Users should therefore upgrade Telegram Desktop to version 7.2.9 or later.
Until the update is installed, users can reduce their exposure by:
- Avoiding unexpected links that launch Telegram Desktop.
- Disabling automatic file downloads where possible.
- Restricting who can add them to Telegram groups.
- Enabling a local Telegram passcode.
- Reviewing active Telegram sessions for anything unfamiliar.
A public PoC shows that the vulnerability can be exploited under certain conditions, but it does not by itself confirm that attackers are actively using the flaw in real-world campaigns.
The main takeaway is simple: Telegram Desktop users should update to the latest version and avoid opening suspicious links that attempt to launch the application.