A vulnerability in Telegram Desktop has come into the public eye through a proof of concept (PoC) that allows attackers to take over accounts and exfiltrate local files with just one click. The flaw, tagged CVE-2026-107181, affects versions prior to 7.2.9 and is rated “High” with a severity score of 8.6 under CVSS 4.0 standards. This exploit is particularly dangerous for users who haven’t enabled a local passcode in Telegram.
What the Flaw Entails
The vulnerability stems from how Telegram Desktop handles links initiated outside the app. When Telegram is already running, it receives external links via an internal channel called inter-process communication (IPC). Attackers can inject special characters—specifically record separators—into crafted links that trick Telegram into misreading link parts as commands. This flaw is classified as CWE-143, which involves improper handling of record delimiters.
Once exploited, the injected command can invoke a legacy internal helper tool meant for release publishing, which lacks proper permission checks. This helper can then read sensitive files from the local system and forward them to a chat without user consent—opening the door to session theft and full account takeover.
Demonstration & Scope
The researcher tested the exploit on Windows using version 6.9.3 of Telegram Desktop and confirmed that the issue persisted through version 7.2.8. There has been no proof yet of the exploit working on macOS or Linux. The attack only succeeds when a user clicks on the manipulated link outside Telegram—such as through a browser. Internal Telegram links are processed differently and are not vulnerable.
Several configuration settings must be in place to pull off a so-called “one-click” attack: automatic group file downloads must be enabled, and the user must allow anyone to add them to group chats. Without these, the exploit’s effectiveness is reduced.
Patch & Mitigations
The issue has been addressed in Telegram Desktop version 7.2.9, released on September 17, 2026. The fix removes the vulnerable helper, adds escaping for record separators, and improves handling of mixed record types. Although the changelog hinted at rendering fixes, it didn’t explicitly mention the security vulnerability.
In the meantime, users are advised to upgrade to 7.2.9 or later. Additional defenses include disabling automatic downloads, restricting group invitations, using a local passcode, and being cautious about browser prompts to open Telegram. If users suspect they may have been compromised, they should close other active sessions and watch for unexpected file uploads in chats.
So far, there are no reports of this flaw being exploited in the wild and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) hasn’t added it to its Known Exploited Vulnerabilities catalog. Still, the publicly released PoC confirms that the vulnerability is real and exploitable.
While this flaw demands prompt attention, users who are protected by updates or stricter settings have solid defenses. Businesses and individuals should audit Telegram configurations and ensure they’re running the latest version. In a broader sense, this incident underscores how legacy components and IPC channels can be weak links in app security.