Skip to content

Telegram Desktop Exposes High-Risk Vulnerability: Clicking a Malicious Link Can One-Click Steal Any Local Files and Sessions, Crypto Community Users Advised to Update Immediately

Oct 9, 19:38

October 9 — Security researcher beaksec (Emiliano Versini) recently disclosed a high-risk vulnerability in Telegram Desktop (CVE-2026-107181), affecting version 7.2.8 and earlier. Attackers can craft malicious tg:// links; after a user clicks them from an external environment such as a browser, IPC injection can be used to read arbitrary local files (including tdata session files) and send them to the attacker's channel, potentially leading to account takeover. The vulnerability has been fixed in version 7.2.9.

As a large number of project teams, communities, and trading groups in the cryptocurrency community rely on Telegram, sensitive information such as wallet mnemonic phrases, private key screenshots, and transaction records is often stored locally. Please immediately check and update Telegram Desktop to the latest version, do not click unknown links at will, and it is recommended to enable local password protection for sessions to reduce the risk of theft.