Eine Schwachstelle in Telegram Desktop ermöglicht das Senden beliebiger Dateien durch Klicken auf einen Link

Details and the method of exploitation of the vulnerability (CVE-2026-107181) in Telegram Desktop, the official Telegram client for desktop systems, have been revealed. The issue was caused by improper handling of unescaped delimiter characters in IPC commands, allowing an attacker to transfer any files from the victim's system, including files with session keys that can be used to take over the Telegram account, by clicking on a sent link. The vulnerability has been fixed in Telegram Desktop version 7.2.9.

When clicking on 'tg://' links, the operating system launches the application associated with this type of link, Telegram Desktop. If another instance of the application is already running, the running process sends the link to it via socket using the IPC interface. The problem is that if the ';' character is included among the link parameters (for example, 'tg://x?a=1;OPEN…'), the content is split, and the parts after the ';' character are processed as separate commands.

To carry out the attack, the OPEN command is used along with the URI scheme 'interpret:', which is intended to launch service scripts via IPC that were used for the automated sending of new releases to channels. The script is a predefined local file containing the file to be sent to the channel and the channel identifier. The file path to the scripts is processed relative to the service subdirectory, but due to the lack of sanitization of '../' in file paths, the attacker can access files saved outside the base directory. For example, a file can be uploaded to their Telegram group, and then this file can be referenced as a script by preparing a link like:

tg://x?a=1;OPEN:interpret:../../../Downloads/Telegram%20Desktop/instructions.txt

Steps to perform the attack:

  • The attacker adds the victim to their group (under default settings, adding does not require confirmation from the added user) and sends a text file to this group that specifies the channel and the script path. Telegram will save this file in a predefined system subdirectory once the victim enters the group.

    channel: 2005234537
    file: tdata/D877F783D5D3EF8Cs

  • The attacker sends the victim an innocuous-looking link to their host (for example, 'https://coolsite.org'), which upon opening is redirected to Server the attacker is replaced with a URI of the form 'tg://x?a=1;OPEN:interpret:…;OPEN:interpret:….'
  • Beim Klicken auf den Link ruft der Browser den URI-Handler „tg://“ auf, der die oben erwähnte Kette von Befehlen startet, die dazu führt, dass Dateien an den Angreifer gesendet werden, ohne irgendwelche Benachrichtigungen anzuzeigen und ohne um eine Bestätigung für den Versand zu bitten.
  • Nachdem die Dateien aus dem Unterverzeichnis tdata mit den Verschlüsselungs- und Autorisierungsschlüsseln erhalten wurden, kann der Angreifer, wenn kein lokales Passwort vom Benutzer festgelegt wurde, die Verbindungssitzung des Opfers auf seinem eigenen Gerät klonen.

Quelle: opennet.ru

Zuverlässiges Hosting für Websites mit DDoS-Schutz kaufen, VPS VDS Server 🔥 Zuverlässiges Hosting für Websites mit DDoS-Schutz kaufen, VPS VDS Server - ProHoster