Telegram Desktop vulnerability allowed any user's file to be stolen
Telegram Desktop vulnerability allows any user's file to be stolen. An attacker can craft a link that, when clicked, results in the victim's Telegram account being compromised. The link arrives as multiple commands, and the third command enables an attacker to read and send any file from the victim's machine to a chat. This occurs due to an injection vulnerability and the lack of authorization checks within Telegram Desktop.
The flaw allows the attacker to read any file on the victim's disk, without needing their credentials or any additional foothold. The only requirement is for the attacker to trick the victim into clicking a malicious link in a group or broadcast channel.
Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.