← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Telegram Desktop Vulnerability Allowed Remote File Theft via Malicious Links

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Vulnerability in Telegram Desktop allowed file theft.
  • Exploited local socket communication and internal URI scheme.
  • A crafted link could trigger arbitrary file reads.
  • No user confirmation was required for file transmission.

Vulnerability Details

A security flaw in Telegram Desktop enabled attackers to steal files from users. The vulnerability stemmed from how the application processes clicked links when an instance is already running. Telegram Desktop communicates between instances using a local socket, sending link information as text.

The core issue involved improper escaping of the character used to separate commands in this inter-process communication. This allowed a crafted link to be interpreted as multiple instructions, rather than a single one.

Exploiting Internal URI Scheme

The injected commands targeted an internal URI scheme, `interpret:`, which is designed to read a specified file and send it to a chat. Crucially, this scheme lacked checks for who initiated the request and did not require user confirmation before transmitting the file.

Combining the injection flaw with this internal URI scheme allowed an attacker to turn a simple clicked link into an arbitrary file read operation, effectively stealing files from the victim's system.

Mechanism of Attack

When Telegram Desktop is already running, a newly launched instance (triggered by clicking a `tg://` link) acts as a client and attempts to connect to the existing instance (the server) via a local socket. The link's URL object is serialized into a text string for transmission across this socket.

Telegram uses a custom serialization format where each instruction is a keyword, its argument, and a semicolon terminator. The vulnerability arose because the semicolon was not properly escaped, allowing an attacker to inject additional commands into the serialized string.

Impact

This vulnerability meant that a user clicking a malicious link could unknowingly have their files, including sensitive login information, exfiltrated. The lack of confirmation prompts made the attack stealthy and effective.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 10

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A vulnerability in Telegram Desktop allowed attackers to steal any user's file by crafting a malicious link. The flaw exploited how Telegram Desktop handles inter-process communication and an internal URI scheme, enabling arbitrary file reads without user confirmation.