Back
Telegram Desktop Flaw Lets Attackers Hijack Accounts With a Single Click
SiTech AI Team2 min read

Telegram Desktop Flaw Lets Attackers Hijack Accounts With a Single Click

A critical vulnerability in Telegram Desktop versions before 7.2.9 lets attackers run hidden commands through crafted links, steal session files, and take over accounts with one click.

How the vulnerability works

A security researcher who goes by the alias BeakSEK discovered that Telegram Desktop versions before 7.2.9, released on September 17, 2026, fail to properly escape semicolons in links. Telegram itself uses the semicolon character to separate instructions, so attackers can inject malicious commands into crafted tg:// links that the application treats as legitimate.

The flaw is rated 8.6 out of 10 on the CVSS severity scale and has been assigned CVE-2026-10718. According to the NIST National Vulnerability Database, attackers can reach the interpret: scheme handler, an internal feature designed for trusted use by Telegram developers that can read any file on disk and send it to chat without asking for confirmation. The feature did not verify who requested the action. Only four commands are available to attackers, and three of them are harmless.

What an attack looks like

In a proof of concept, the researcher creates a supergroup on Telegram and adds victims, which Telegram's default privacy settings allow. The attacker posts three crafted instruction .txt files, which Telegram automatically downloads to victims' machines, since the default configuration downloads files received in groups up to 8 MiB automatically.

The attacker then posts a link that may appear innocuous but redirects to a malicious tg: link containing injected commands. If a victim clicks it, the system launches a second Telegram process and the command execution fires. The three instruction files specify what to exfiltrate: the local encryption key, session authorization data, and the index of the account's stored data. Relative paths allow locating the files without knowing the victim's Windows username.

The attacker can then drop the stolen files into a fresh Telegram instance and restore the victim's session, assuming no local passcode was set.

How to protect yourself

BeakSEK urges users to update Telegram Desktop to the latest available version and limit who can add them to groups. The researcher also recommends setting a local passcode and turning on the "ask where to save each file" option, which stops automatic file downloads. The latest Telegram version is 7.3, released on October 9, 2026, with only one word in the release notes: "Money."

Sources: Cybernews

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.