Telegram Desktop one-click file theft is CVE-2026-107181
A researcher write-up shows how one click on a crafted external link could make Telegram Desktop before 7.2.9 send local files, including session data, to an attacker chat. CVSS 4.0 8.6 (VulnCheck). Fixed in 7.2.9 without a vendor advisory. Public PoC write-up exists. Not in CISA KEV; no known exploitation.
Published 9 Oct 2026
What happened
On 3 October 2026 security researcher beaksec published a technical write-up describing a one-click account takeover in Telegram Desktop, updated on 7 October. VulnCheck, acting as CNA, assigned CVE-2026-107181 on 7 October 2026 and classifies it as CWE-143, improper neutralization of record delimiters. Telegram Desktop hands links opened from outside the app to its already-running instance over a local single-instance channel, and that channel did not escape its record separator. A crafted link could therefore inject an extra command. According to the write-up, that command reached a legacy internal helper, originally used for release publishing, which reads a local file and sends it to a chat without any authorization check or confirmation prompt.
The outcome is arbitrary local file read and exfiltration to an attacker-controlled chat. Because the files that can be taken include Telegram's local session data, the researcher shows this leading to account takeover when the user has not set a local passcode.
Who is affected
The CVE record lists Telegram Desktop before 7.2.9 as affected and 7.2.9 as unaffected. The researcher states the issue exists through 7.2.8 and confirmed the chain on Windows, testing version 6.9.3. The CVE covers Telegram Desktop only. Links clicked inside Telegram itself are handled in-process and are not affected.
The attack needs one click on a link opened outside Telegram, for example in a web browser, which may show a confirmation prompt before launching the desktop app. The researcher's chain also relies on two defaults: files in groups are downloaded automatically, and anyone can add the user to a group.
What is confirmed
Telegram fixed the issue in commit db3405699f on 16 September 2026 and published Telegram Desktop 7.2.9 on 17 September 2026. The fix removes the legacy helper, escapes the IPC separator, and adds extra hardening when different record types arrive on the same connection. VulnCheck scores the CVE CVSS 4.0 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N) and CVSS 3.1 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N), both High. NVD lists the record as Awaiting Analysis. GitHub carries it as unreviewed advisory GHSA-2h6w-ccjh-5jhr. The CVE is not in the CISA KEV catalog, and CISA's SSVC entry sets exploitation to poc.
The write-up was published by researcher beaksec and contains a step-by-step proof of concept. It claims a one-click chain that leads to arbitrary local file read and Telegram account takeover on Windows. ThreatWire did not run it. Availability is therefore PoC. This article does not reproduce links, file formats, paths, or steps from the write-up.
What is not confirmed
The researcher confirmed the chain on Windows only. The CVE record covers Telegram Desktop generally, but macOS and Linux builds were not demonstrated in the write-up. Telegram has published no security advisory, and the 7.2.9 changelog mentions only a rendering fix, so there is no vendor statement on scope or exploitation. The researcher reported the bug through ZDI on 25 June 2026; the vendor fixed it independently and ZDI closed the case as already fixed on 30 September.
ThreatWire found no reports of exploitation in the wild, and CISA has not listed the CVE. On scoring, a post circulating the bug cited 8.6 while the researcher cites 8.1. Both come from VulnCheck's record: 8.6 is the CVSS 4.0 score and 8.1 the CVSS 3.1 score, so the gap reflects the scoring version, not a disagreement. NVD has not published its own score.
What to do
Update Telegram Desktop to 7.2.9 or later on every machine, and confirm the version under Settings, then About. Until every install is updated, enable the option to ask where to save each file, which stops automatic downloads, and restrict who can add you to groups to your contacts. Set a local passcode so that stolen session files are harder to reuse.
Treat links that open Telegram from a browser with caution, and decline the browser's launch prompt for links you did not expect. If you ran a vulnerable version and suspect you opened such a link, end other sessions from Telegram's active sessions list and review recent chats for files you did not send.
Sources: Telegram Desktop fix commit db3405699f and v7.2.9 release, VulnCheck advisory, NVD and CVE.org for CVE-2026-107181, GHSA-2h6w-ccjh-5jhr, CISA KEV (not listed), and the researcher's public write-up.