Skip to content

BuildNot yet confirmed elsewhere1 publisher2 min readPublished

Telegram Desktop's missing semicolon escape turned a clicked link into session theft

Telegram Desktop 7.2.9 patches CVE-2026-107181, a CVSS 8.1 flaw where one clicked link in a group chat could steal a victim's logged-in account session. Every build up to 7.2.8 is vulnerable, so the fix helps a machine only once the patched client is installed.

The Engineer · Build desk

How we use AISend a correction

What happened

  • The exploit chained two bugs that are harmless alone: an injection into the client's internal IPC channel, and a publishing command inherited from Telegram's own tooling that never asked for confirmation.
  • interpret: existed so a release script could name a destination channel and a build file and have Telegram Desktop upload it with its changelog, with no manual step for anyone.
  • A from: field meant to block publishing from the wrong account runs only when that line is present, so an attacker simply leaves it out and the check never fires.
  • The researcher who reported the flaw followed responsible disclosure, publishing the technical writeup only after the fix, commit db3405699f, had reached all users.

Why it matters

  • decision A client stays exploitable until it is actually running 7.2.9, so patching the fleet means confirming the installed version on each machine, not assuming the update already landed.
  • constraint The whole exchange happens between two local processes, so Telegram's encryption and servers never touched the payload and no network-side control could have blocked it.
  • exposure Session theft is the demonstrated payload, but the same read primitive reaches any file on the machine, so posting a link in a shared group gives a sender a read of the target's disk.
  • precedent Because the root cause is an IPC serializer that does not escape its terminator, any other command reachable over that socket is a candidate for the same injection until the serializer itself is fixed.

Telegram Desktop is Telegram's official client for Windows, macOS and Linux, and it registers a tg:// scheme so the operating system can hand links to it [16]. Click one and the OS does not check whether the client is already open; it starts a fresh process regardless [8]. That process tries to connect to a local socket, and a successful connection means an instance is already live, so it passes the link across and exits [8]. Messages on that socket use a plain format: a keyword, an argument, and a semicolon to end the instruction [9].

The serializer does not escape that semicolon [10]. An attacker who controls the argument can close the first instruction and append a second, and the second one calls interpret:, a scheme the operating system refuses to register that the client parses on the fly like any other startup link [11]. That command reads the file holding the victim's active session and uploads it to a channel the attacker controls, with no confirmation prompt [15]. The destination field only has to name a real channel or supergroup [14].

The report gives the CVSS 3.1 vector as "AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N": remote, low complexity, no privileges, and user interaction required [5]. The required interaction is the click, and the rating records no impact on availability [4].

The researcher, who publishes as beaksec, tracked the flaw up to 7.2.8 and confirmed it on the Windows build 6.9.3 [3][2].

What to watch

  • Whether other commands reachable over the same IPC socket prove injectable before the serializer is hardened.
  • Whether Telegram removes interpret: from shipped clients or scopes it to release tooling only.
  • Confirmation of the flaw and the fix on macOS and Linux, which the report tracks only on the Windows build 6.9.3.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence40
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    A click on a link inside a group chat was enough for an attacker to read any file on the victim's computer and, with it, steal the active session of the account.

    ReportedSupportedView cited source
  2. [2]

    The vulnerability is catalogued as CVE-2026-107181 and was found by a researcher publishing under the pseudonym beaksec.

    ReportedSupportedView cited source
  3. [3]

    The affected versions reach up to 7.2.8, confirmed on the Windows build 6.9.3.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 10, 2026

    Telegram Desktop 7.2.9 corrige CVE-2026-107181 de robo de cuenta

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories