Telegram Desktop vulnerability allowed any user's file to be stolen

A security vulnerability in Telegram Desktop allowed attackers to steal arbitrary files from a user's computer by exploiting how the application handles clicked links. By injecting malicious commands into the local socket communication, an attacker could bypass security checks to access sensitive session files.
Why it matters
This flaw demonstrates the risks associated with inter-process communication in desktop applications and the potential for remote code execution or data theft via simple user interaction.
An unescaped separator in Telegram Desktop's single-instance IPC lets one clicked link read arbitrary files off the disk and send them to the attacker, session files included.
Someone adds you to a Telegram group. A link shows up in the chat. You click it, and your Telegram account is no longer only yours.
Telegram Desktop hands clicked links to its own already-running instance over a local socket, as text, and never escapes the character it uses to separate commands. So a crafted link does not arrive as one instruction: it arrives as several.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in