Telegram Desktop vulnerability allowed any user's file to be stolen
Article URL: https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/ Comments URL: https://news.ycombinator.com/item?id=50029123 Points: 229 # Comments: 116
A vulnerability in Telegram Desktop allowed any user's files to be stolen. When someone added a user to a Telegram group and sent a link in the chat, clicking the link gave the attacker access to the user's account. Telegram Desktop forwarded the clicked links to its own instance over a local socket, where they were never separated by a unique character.
This allowed an injection attack, where a crafted link could read and send any file to a chat without checking the requester or requiring confirmation. The operating system registers URI schemes, so when Telegram Desktop registered tg., the system knew that tg:// links belonged to Telegram and launched them with the URL as a command-line argument.
If Telegram was already running, the system launched a new process, which made it vulnerable to the same attack. The second defect was that the injected command reached an internal URI scheme, interpret:, which read a file named in an instruction file and sent it to a chat without a confirmation. An attacker could place an instruction file on the victim's disk and exfiltrate any file from their machine with a clicked link, exploiting the missing authorization check.
Written by urgent.news from Hacker News Best's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Telegram Desktop vulnerability allowed any user's file to be stolen beaksec.github.io