Someone adds you to a Telegram group. A link appears in the chat. You click it, and your Telegram account is no longer only yours. That is how security researcher Emiliano Versini, who publishes under the alias BeakSEK, described the attack chain he disclosed this week. The flaw, tracked as CVE-2026-107181 with a CVSS severity score of 8.6, affected Telegram Desktop versions through 7.2.8 and let an attacker steal a victim's session files and take over their account with a single click.

Telegram is used by roughly a billion people a month, and its desktop client is how many of them read and send messages all day. The bug is a case study in how two individually modest defects can combine into something serious, and in how a silent patch can leave the most important detail out of the story.

Defect one: a separator nobody escaped

The first defect sits in how Telegram Desktop handles links clicked outside the app, for example in a browser. Telegram Desktop registers the tg:// URL scheme with the operating system. When you click such a link, a second process launches, connects to the already-running instance over a local socket, and forwards the URL. This is single-instance inter-process communication, an ordinary pattern. But Telegram's serialization was homemade: keyword, argument, and a raw semicolon as the record terminator. An instruction on the wire looks like OPEN:tg://x?a=1;, and the running instance splits at every semicolon and treats each fragment as a separate command.

The semicolon was never escaped. A semicolon that is perfectly legal inside a tg:// query therefore became a second command on the other side of the wire. One crafted URL, two (or more) commands executed. BeakSEK's one-sentence description of the injection is among the best of its kind: the URL is only a carrier, and once data crosses into the record, the boundaries inside the data stop being held by the structure and become characters in the text. It is classified as CWE-143, improper neutralization of record delimiters, the same class of mistake as SQL injection, one layer down.

Defect two: the forgotten tool

Enjoying this story?

Get the five most important stories in tech, every morning. Free.

An injected command by itself is only useful if it can reach something powerful. It could. The injected records reach an internal interpret: URI scheme handler, a leftover helper built for Telegram's automated release publishing. That helper reads an instruction text file with channel:, file:, and caption: fields, then reads any file on disk and uploads it to the named chat. No user confirmation. No check on who asked. The optional from: verification field is skipped entirely when it is omitted.

So the exploit works in seven steps, per the published proof of concept. The attacker creates a supergroup and adds the victim. Telegram's auto-download pulls a few crafted instruction files into the victim's Downloads folder. A message contains a link that redirects, via an ordinary 302 from an https URL, onto a stacked tg:// payload. The victim clicks once. The injected interpret: command runs, reads three session files out of the tdata folder, and uploads them to the attacker's channel. Those three files are the entire account, including the local encryption keys that protect it. On a fresh machine, they restore the account for whoever holds them.

The URL is only a carrier. Once data crosses into the record, the boundaries inside the data stop being held by the structure and become characters in the text.

The attack has real prerequisites

The Telegram Desktop Flaw at a Glance

CVE-2026-107181, based on researcher disclosures and the NVD entry.

CVSS severity
8.6 / 10
Versions affected
Through 7.2.8
Defects chained
2
Clicks required
1

Note: For illustrative purposes only.

This was not a zero-click drive-by. The proof of concept only worked under specific conditions, and they are worth stating plainly. The attacker's link had to be clicked outside Telegram, in a browser, because links opened inside the app are processed through a different path that was not vulnerable. The victim's group auto-download had to be on, so the instruction files landed on disk. Anyone had to be allowed to add the victim to groups. And the victim had to have no local passcode set, because the passcode wraps the session files and blocks the theft. BeakSEK confirmed the exploit on Windows through version 7.2.8; macOS and Linux were not demonstrated, and there is no confirmed in-the-wild exploitation or CISA KEV listing as of October 9.

None of that diminishes the lesson. Prerequisite stacks are how real attacks work: each condition shaves the target population, but Telegram's billion-user base means even a narrow slice is a very large number of people. And the conditions were all defaults or common settings.

The fix that nobody noticed

Messaging and social network connections
A single clicked link in Telegram Desktop could hand an attacker the keys to your account. (Photo: Shutterstock)

Versini reported the bug to the Zero Day Initiative on June 25. The writeup landed publicly on October 3, and the CVE followed on October 7. The patch itself had shipped even earlier: Telegram Desktop 7.2.9, released September 17, fixed the injection by commit db3405699f. The changelog that shipped the fix to hundreds of millions of users described it as a rendering improvement. The latest version, 7.3, released October 9, came with a single word of release notes: "Money."

Quiet patching is not unusual, and there are defensible reasons for it: announce nothing, and attackers cannot diff the patch to build an exploit. But the silence had a cost. Users who clicked through on September 17 had no reason to suspect the update was a security fix, and users who skip optional updates heard nothing that would make them reconsider. The tension between responsible silence and informed users is an old one, and this week it played out at scale: a vulnerability affecting one of the world's most-used messaging apps was fixed, disclosed, and exploited in proof-of-concept form all while the official release notes said essentially nothing.

What to do now

The remediation is straightforward. Update Telegram Desktop to 7.2.9 or later (7.3 is current). Set a local passcode in Settings, which encrypts the session files on disk and would have blocked the theft outright. Restrict who can add you to groups, and turn off automatic media downloads in group chats, which denies the attack its file staging step. None of these steps is new advice, but this vulnerability is a reminder of why they exist: defense in depth means an attack needs every prerequisite, and removing any one of them breaks the chain.

There is a broader lesson for software teams too. The interpret: handler was an internal tool that never should have been reachable from untrusted input, and the IPC format was a homegrown serialization where a standard escaping discipline would have prevented the bug entirely. Two small engineering decisions, one from years ago, combined into a one-click account takeover. The semicolon is harmless in a URL. It was never harmless in that socket.