BuildNot yet confirmed elsewhere1 publisher2 min readPublished
Telegram Desktop's missing semicolon escape turned a clicked link into session theft
Telegram Desktop 7.2.9 patches CVE-2026-107181, a CVSS 8.1 flaw where one clicked link in a group chat could steal a victim's logged-in account session. Every build up to 7.2.8 is vulnerable, so the fix helps a machine only once the patched client is installed.
The Engineer · Build desk
What happened
- The exploit chained two bugs that are harmless alone: an injection into the client's internal IPC channel, and a publishing command inherited from Telegram's own tooling that never asked for confirmation.
- interpret: existed so a release script could name a destination channel and a build file and have Telegram Desktop upload it with its changelog, with no manual step for anyone.
- A from: field meant to block publishing from the wrong account runs only when that line is present, so an attacker simply leaves it out and the check never fires.
- The researcher who reported the flaw followed responsible disclosure, publishing the technical writeup only after the fix, commit db3405699f, had reached all users.
Why it matters
- decision A client stays exploitable until it is actually running 7.2.9, so patching the fleet means confirming the installed version on each machine, not assuming the update already landed.
- constraint The whole exchange happens between two local processes, so Telegram's encryption and servers never touched the payload and no network-side control could have blocked it.
- exposure Session theft is the demonstrated payload, but the same read primitive reaches any file on the machine, so posting a link in a shared group gives a sender a read of the target's disk.
- precedent Because the root cause is an IPC serializer that does not escape its terminator, any other command reachable over that socket is a candidate for the same injection until the serializer itself is fixed.
Telegram Desktop is Telegram's official client for Windows, macOS and Linux, and it registers a tg:// scheme so the operating system can hand links to it [16]. Click one and the OS does not check whether the client is already open; it starts a fresh process regardless [8]. That process tries to connect to a local socket, and a successful connection means an instance is already live, so it passes the link across and exits [8]. Messages on that socket use a plain format: a keyword, an argument, and a semicolon to end the instruction [9].
The serializer does not escape that semicolon [10]. An attacker who controls the argument can close the first instruction and append a second, and the second one calls interpret:, a scheme the operating system refuses to register that the client parses on the fly like any other startup link [11]. That command reads the file holding the victim's active session and uploads it to a channel the attacker controls, with no confirmation prompt [15]. The destination field only has to name a real channel or supergroup [14].
The report gives the CVSS 3.1 vector as "AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N": remote, low complexity, no privileges, and user interaction required [5]. The required interaction is the click, and the rating records no impact on availability [4].
The researcher, who publishes as beaksec, tracked the flaw up to 7.2.8 and confirmed it on the Windows build 6.9.3 [3][2].
What to watch
- Whether other commands reachable over the same IPC socket prove injectable before the serializer is hardened.
- Whether Telegram removes interpret: from shipped clients or scopes it to release tooling only.
- Confirmation of the flaw and the fix on macOS and Linux, which the report tracks only on the Windows build 6.9.3.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence40
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
A click on a link inside a group chat was enough for an attacker to read any file on the victim's computer and, with it, steal the active session of the account.
- [2]
The vulnerability is catalogued as CVE-2026-107181 and was found by a researcher publishing under the pseudonym beaksec.
- [3]
The affected versions reach up to 7.2.8, confirmed on the Windows build 6.9.3.
- [4]
CVSS 3.1 rated the flaw 8.1 out of 10 (high severity), with no impact on availability.
- [5]
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N: remote attack, low complexity, no prior privileges, but mandatory user interaction (the click on the link).
- [6]
The fix shipped in version 7.2.9, identified in the project repository by commit db3405699f.
- [7]
The flaw combined two separately-harmless bugs: an injection into the client's internal IPC channel, and a command inherited from Telegram's publishing tools that never asked for confirmation.
- [8]
When a user clicks a tg:// link the OS does not know whether Telegram Desktop is open; it launches a new process anyway, which connects to a local socket and, if an instance is already active, hands over the link and closes.
- [9]
The inter-process communication uses a simple format: a keyword, its argument, and a semicolon that closes the instruction.
- [10]
The serialization format used by Telegram Desktop's IPC does not escape the semicolon.
- [11]
interpret: is a scheme the operating system does not recognise as a protocol and that is not registered in any external handler, but which Telegram's own code interprets on the fly like any other startup link.
- [12]
interpret: began as an internal tool: when the team published a new version, a script built a text file with the destination channel and the file to send, launched Telegram Desktop pointing at it, and the client uploaded the build with its changelog to the official channel with nobody dragging a file by hand.
- [13]
The instruction file admits a from: field that compares the logged-in account id against an expected id, but that comparison only runs if the from: line is present; omitting it skips the check entirely.
- [14]
The destination, controlled by the channel: field, only requires it to be a real channel or supergroup.
- [15]
Used maliciously via IPC injection, any sender who sneaks a second command into the link reads a local file and sends it to a chat the victim does not control, without a confirmation prompt.
- [16]
Telegram Desktop is Telegram's official desktop client for Windows, macOS and Linux, developed by Telegram FZ-LLC; it syncs chats and session with the app cloud and exposes a tg:// link scheme to open commands from the operating system.
- [17]
The report followed responsible disclosure: the researcher warned before publishing the technical details, and the blog entry appeared only once the fix was available to all users.
- [18]
The problem is not in the encryption or Telegram's servers but in how two processes of the same program talk to each other on the victim's computer.
- [19]
A client running 7.2.8 or any earlier build remains exploitable until it is upgraded to 7.2.9.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toTelegram Desktop 7.2.9 corrige CVE-2026-107181 de robo de cuenta
1 article · October 10, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- IPC injectionFollow
- Coordinated Vulnerability DisclosureFollow
- Consumer messaging app securityFollow