Skip to content

BuildNot yet confirmed elsewhere1 publisher2 min readPublished

Telegram Desktop let one clicked link copy a whole account over its local socket

Telegram Desktop patched a flaw, rated CVSS 8.1, that let a single clicked link ship a user's whole account to an attacker's channel. The fix reached hundreds of millions of users in September, described in the changelog as a rendering improvement.

The Engineer · Build desk

How we use AISend a correction

What happened

  • The researcher reported the flaw to the Zero Day Initiative on June 25, it was fixed by September 17, and the public writeup, CVE and proof-of-concept all followed in October.
  • Telegram Desktop registers the tg:// scheme, and clicking such a link launches a second process that forwards the URL to the already-running instance over a local socket.
  • That local channel ends each command with a semicolon and never escapes a semicolon inside the forwarded URL, so one crafted link is parsed as two commands.
  • The attack is seeded from a supergroup the victim is silently added to, where default auto-download pulls plain-text instruction files under 8 MiB into the local Downloads folder.
  • The three stolen files, key_datas, the D877F783D5D3EF8Cs authorization and its maps index, drop into a fresh tdata folder on any machine as the victim's live session.

Why it matters

  • constraint Teams that triage patches by reading changelogs had nothing to flag, because the entry described a rendering improvement and CVE-2026-107181 was published about three weeks after the fix had already shipped.
  • exposure An attacker who lands the three files gets a working session and is inside the account on any computer, without the victim's password or second factor.
  • precedent The writeup puts prompt injection in the same class as this bug, data carrying its own delimiter, so the same escaping failure recurs anywhere tool output can contain control tokens.

The injection is in how the handler packs a URL for transport. Telegram Desktop's second process serializes commands as keyword, argument and a semicolon terminator, so OPEN:tg://x?a=1; is one command, and the receiving instance splits on every semicolon and runs each fragment. [7] The semicolon is never escaped when the URL is embedded, so tg://x?a=1;CMD:quit arrives as a single URL and parses as two commands. [8]

The researcher put the whole bug in one line. The URL "is only a carrier," they wrote, and once data crosses into the record "the boundaries inside the data stop being held by the structure and become characters in the text." [9]

The stacked command can reach interpret:. It is a legacy internal scheme wired to InterpretSendPath in support_helper.cpp, a helper from the workflow Telegram uses to publish releases. Given a file, it opens it and sends it on, checking no permissions and asking nobody to confirm. [13] The injected command uses a relative path, ../../../Downloads/Telegram Desktop/instructions1.txt, which resolves from the data directory, so no username is needed. [12] The plain-text instruction files, auto-downloaded earlier from the attacker's supergroup, tell the helper which files to read and where to send them. [10]

Links clicked inside Telegram never reach the socket, so the attack needs the operating system browser as a relay: the victim clicks an ordinary https:// link, and the attacker's server answers with a 302 redirect to a tg:// URL carrying the stacked commands. [11]

This is injection of the oldest kind, a serialization boundary where data is allowed to contain the delimiter. The writeup lines it up with CSV formula injection, CRLF in mail headers, HTTP response splitting, shell word splitting and SQL concatenation, each one a payload carrying an unescaped separator. [15] It argues prompt injection belongs to the same family, with natural language as the delimiter and the model's context window as the channel. [16]

A helper that only read files for the build pipeline had become a remote file-transfer service for anyone who could name a path. [19] The fix is narrow. Commit db3405699f, titled "Remove legacy interpret path helper," touches 11 files for +126/-372 and adds EscapeTo7bit and EscapeFrom7bit, percent-encoding every character below 32, above 127, or equal to % or ;. [17] It also drops local file paths entirely when a non-local URL shares the connection. [18]

What to watch

  • Whether vulnerability trackers reconcile the September fix with the October 7 CVE so patch-triage tooling flags affected builds.
  • Whether the public proof-of-concept drives exploitation before users on pre-fix builds update.
  • Whether other single-instance IPC handlers using semicolon-terminated commands get audited for the same unescaped-delimiter bug.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption62
Hype gap+8
Incentives55
Confidence58
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    A researcher reported to the Zero Day Initiative on June 25 that a single clicked https:// link could read three files from a Telegram Desktop user's machine and ship them to an attacker's channel.

    ReportedSupportedView cited source
  2. [2]

    The bug was fixed by September 17, and the changelog that shipped the fix to hundreds of millions of users described it as a rendering improvement.

    ReportedSupportedView cited source
  3. [3]

    The public writeup of the bug was published October 3 by beaksec.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 10, 2026

    One unescaped semicolon was enough to steal Telegram accounts

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories