BuildNot yet confirmed elsewhere1 publisher2 min readPublished
Telegram Desktop let one clicked link copy a whole account over its local socket
Telegram Desktop patched a flaw, rated CVSS 8.1, that let a single clicked link ship a user's whole account to an attacker's channel. The fix reached hundreds of millions of users in September, described in the changelog as a rendering improvement.
The Engineer · Build desk
What happened
- The researcher reported the flaw to the Zero Day Initiative on June 25, it was fixed by September 17, and the public writeup, CVE and proof-of-concept all followed in October.
- Telegram Desktop registers the tg:// scheme, and clicking such a link launches a second process that forwards the URL to the already-running instance over a local socket.
- That local channel ends each command with a semicolon and never escapes a semicolon inside the forwarded URL, so one crafted link is parsed as two commands.
- The attack is seeded from a supergroup the victim is silently added to, where default auto-download pulls plain-text instruction files under 8 MiB into the local Downloads folder.
- The three stolen files, key_datas, the D877F783D5D3EF8Cs authorization and its maps index, drop into a fresh tdata folder on any machine as the victim's live session.
Why it matters
- constraint Teams that triage patches by reading changelogs had nothing to flag, because the entry described a rendering improvement and CVE-2026-107181 was published about three weeks after the fix had already shipped.
- exposure An attacker who lands the three files gets a working session and is inside the account on any computer, without the victim's password or second factor.
- precedent The writeup puts prompt injection in the same class as this bug, data carrying its own delimiter, so the same escaping failure recurs anywhere tool output can contain control tokens.
The injection is in how the handler packs a URL for transport. Telegram Desktop's second process serializes commands as keyword, argument and a semicolon terminator, so OPEN:tg://x?a=1; is one command, and the receiving instance splits on every semicolon and runs each fragment. [7] The semicolon is never escaped when the URL is embedded, so tg://x?a=1;CMD:quit arrives as a single URL and parses as two commands. [8]
The researcher put the whole bug in one line. The URL "is only a carrier," they wrote, and once data crosses into the record "the boundaries inside the data stop being held by the structure and become characters in the text." [9]
The stacked command can reach interpret:. It is a legacy internal scheme wired to InterpretSendPath in support_helper.cpp, a helper from the workflow Telegram uses to publish releases. Given a file, it opens it and sends it on, checking no permissions and asking nobody to confirm. [13] The injected command uses a relative path, ../../../Downloads/Telegram Desktop/instructions1.txt, which resolves from the data directory, so no username is needed. [12] The plain-text instruction files, auto-downloaded earlier from the attacker's supergroup, tell the helper which files to read and where to send them. [10]
Links clicked inside Telegram never reach the socket, so the attack needs the operating system browser as a relay: the victim clicks an ordinary https:// link, and the attacker's server answers with a 302 redirect to a tg:// URL carrying the stacked commands. [11]
This is injection of the oldest kind, a serialization boundary where data is allowed to contain the delimiter. The writeup lines it up with CSV formula injection, CRLF in mail headers, HTTP response splitting, shell word splitting and SQL concatenation, each one a payload carrying an unescaped separator. [15] It argues prompt injection belongs to the same family, with natural language as the delimiter and the model's context window as the channel. [16]
A helper that only read files for the build pipeline had become a remote file-transfer service for anyone who could name a path. [19] The fix is narrow. Commit db3405699f, titled "Remove legacy interpret path helper," touches 11 files for +126/-372 and adds EscapeTo7bit and EscapeFrom7bit, percent-encoding every character below 32, above 127, or equal to % or ;. [17] It also drops local file paths entirely when a non-local URL shares the connection. [18]
What to watch
- Whether vulnerability trackers reconcile the September fix with the October 7 CVE so patch-triage tooling flags affected builds.
- Whether the public proof-of-concept drives exploitation before users on pre-fix builds update.
- Whether other single-instance IPC handlers using semicolon-terminated commands get audited for the same unescaped-delimiter bug.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption62
- Hype gap+8
- Incentives55
- Confidence58
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A researcher reported to the Zero Day Initiative on June 25 that a single clicked https:// link could read three files from a Telegram Desktop user's machine and ship them to an attacker's channel.
- [2]
The bug was fixed by September 17, and the changelog that shipped the fix to hundreds of millions of users described it as a rendering improvement.
- [3]
The public writeup of the bug was published October 3 by beaksec.
- [4]
CVE-2026-107181, with a CVSS score of 8.1, was assigned on October 7.
- [6]
Telegram Desktop registers the tg:// URL scheme; clicking a tg:// link launches a second process that connects to a local socket where the running instance listens and forwards the URL, a single-instance IPC pattern.
- [7]
The channel's serialization is homemade: keyword, argument and a semicolon terminator, as in OPEN:tg://x?a=1;, and the receiver splits at every semicolon and treats each fragment as a command.
- [8]
The semicolon is never escaped when the URL is embedded, so tg://x?a=1;CMD:quit arrives as one URL and the running instance parses it as two commands.
- [9]
The researcher wrote that the URL "is only a carrier," and that once data crosses into the record "the boundaries inside the data stop being held by the structure and become characters in the text."
- [10]
The attacker creates a supergroup, default privacy settings let them add the victim silently, and they post three plain-text instruction files; default auto-download pulls anything under 8 MiB into Downloads/Telegram Desktop/, and the files omit the from: line to skip the account-ID check and name the attacker's channel as destination.
- [11]
Links clicked inside Telegram never reach the socket, so the attack requires the OS browser as a relay: the victim clicks a normal https:// link, and the attacker's server answers with a 302 redirect to a tg:// URL carrying the stacked injected commands.
- [12]
The injected command uses a relative path such as ../../../Downloads/Telegram Desktop/instructions1.txt, which resolves from the data directory, so no username is needed.
- [13]
interpret: is a legacy internal scheme wired to InterpretSendPath in support_helper.cpp, a helper from Telegram's release-publishing workflow that reads a file and sends it with no authorization check and no confirmation.
- [14]
One click copies key_datas, the D877F783D5D3EF8Cs authorization and its maps index, the salt-plus-wrapped-DEK, the MTProto authorization and its index; dropped into a fresh tdata folder on any machine they are the victim's session, the exact equivalent of stealing a session cookie.
- [15]
The writeup frames the flaw as the oldest injection class, a serialization boundary where data is allowed to contain the delimiter, and lists CSV formula injection, CRLF in mail headers, HTTP response splitting, shell word splitting and SQL concatenation as the same pattern, each one the payload containing a separator that nobody escaped.
- [16]
The writeup argues prompt injection is separator injection where the delimiter is natural language and the IPC channel is the model's context window.
- [17]
Telegram's patch, commit db3405699f titled 'Remove legacy interpret path helper,' spans 11 files for +126/-372 and adds EscapeTo7bit/EscapeFrom7bit, percent-encoding every character below 32, above 127, or equal to % or ;.
- [18]
The patch also drops local file paths entirely when a non-local URL shares the connection.
- [19]
The writeup observed that a helper that just reads files for the build pipeline had turned out to be a remote file-transfer service for anyone who could name a path.
- [20]
CVE-2026-107181 was published about three weeks after the fix shipped.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toOne unescaped semicolon was enough to steal Telegram accounts
1 article · October 10, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Vulnerability DisclosureFollow
- Injection VulnerabilitiesFollow
- Session and Cookie HijackingFollow
- Prompt injectionFollow
Entities
- Telegram DesktopFollow
- TelegramFollow
- CVE-2026-107181Follow
- Zero Day InitiativeFollow
- beaksecFollow
- MTProtoFollow