🚨 PoC RELEASED: Telegram Desktop one-click account takeover (CVE-2026-107181)
A researcher has published a full technical write-up and proof of concept for a flaw in Telegram Desktop before 7.2.9.
🔴 CVSS 4.0: 8.6 High (CVSS 3.1: 8.1), scored by VulnCheck
🎯 Root cause (CWE-143): Telegram Desktop’s single-instance IPC didn’t escape its record separator, so a crafted external link could inject extra commands. One of them reached a legacy internal helper that reads a local file and sends it to a chat, with no authorization check and no confirmation.
💥 Impact: one click on an external link can lead to arbitrary local file read. That includes Telegram’s session data, enough to take over the account when no local passcode is set. Confirmed on Windows.
📅 Reported via ZDI in June. Telegram quietly fixed it in 7.2.9 (Sept 17) with no advisory. CVE assigned Oct 7.
Not in CISA KEV. No in-the-wild exploitation reported. ThreatWire has not run the PoC.
✅ Update to Telegram Desktop 7.2.9+. Also consider:
• “Ask where to save each file”.
• Limiting who can add you to groups.
• Setting a local passcode.
Full breakdown & Poc👇
https://www.threatwire.tech/research/telegram-desktop-one-click-file-theft-is-cve-2026-107181
#Telegram #CVE #InfoSec #CyberSecurity
