{
  "id": 13326899,
  "title": "Telegram Desktop vulnerability allowed any user's file to be stolen",
  "url": "https://urgent.news/2026/10/10/telegram-desktop-vulnerability-allowed-any-users-file-to-be-stolen",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-10T03:02:47.000Z",
  "source": {
    "name": "Hacker News",
    "slug": "hacker-news",
    "url": "https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/"
  },
  "original_language": "en",
  "account": "Telegram Desktop vulnerability allows any user's file to be stolen. An attacker can craft a link that, when clicked, results in the victim's Telegram account being compromised. The link arrives as multiple commands, and the third command enables an attacker to read and send any file from the victim's machine to a chat. This occurs due to an injection vulnerability and the lack of authorization checks within Telegram Desktop. The flaw allows the attacker to read any file on the victim's disk, without needing their credentials or any additional foothold. The only requirement is for the attacker to trick the victim into clicking a malicious link in a group or broadcast channel.",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}