Vulnerability In Telegram Desktop That Allows Arbitrary Files To Be Sent When Link Is Clicked

Disclosed details and method of exploitation of the vulnerability (CVE-2026-107181) in Telegram Desktop, the official Telegram client for desktop systems. The problem is caused by the lack of proper processing of unescaped delimiter characters in IPC commands, which made it possible, when clicking on a sent link, to organize the transfer to the attacker of any files from the victim’s system, including files with session keys that can be used to take over a Telegram account. Vulnerability fixed in the release Telegram Desktop 7.2.9.

When you click on “tg://” links, the operating system launches the Telegram Desktop application associated with this type of link. If another instance of this application is already running on the system, then the running process passes the link to it via a socket using the IPC interface. The problem is that if you specify the symbol “;” Among the link parameters (for example, “tg://x?a=1;OPEN…”), the contents are separated and those following the “;” parts are processed as separate commands.

The attack uses the OPEN command along with the “interpret:” URI scheme, designed to run service scripts via IPC that were used to automatically push new releases to channels. The script provides a predefined local file that specifies the file to be sent to the channel and the channel ID. The file path to scripts is processed relative to the service subdirectory, but due to the lack of “../” cleaning in file paths, an attacker is able to access files stored outside the base directory. For example, you can upload a file to your telegram group, and then refer to this file as a script, preparing a link like:

tg://x?a=1;OPEN:interpret:../../../Downloads/Telegram%20Desktop/instructions.txt

Stages of the attack:

  • The attacker adds the victim to his group (with default settings, the addition does not require confirmation from added) and sends a text file to this group, which specifies the channel and path to the script. Telegram will save this file to a predefined system subdirectory when the victim joins the group. channel: 2005234537 file: tdata/D877F783D5D3EF8Cs
  • The attacker sends the victim an innocent-looking link to his host (for example, “https://coolsite.org”), which, when opened through a redirect on the attacker’s server, is replaced with a URI like ‘tg://x?a=1;OPEN:interpret:…;OPEN:interpret:…”.
  • When you click on the link, the browser calls the URI “tg://” handler, which starts the above-mentioned chain of commands, which leads to sending files to the attacker’s channel without displaying any notifications and without asking for confirmation of sending.
  • Having received files from the tdata subdirectory with encryption and authorization keys, in the absence of one set by the user local password, the attacker can clone the victim’s connection session on his device.

/Reports, release notes, official announcements.