{
  "id": 13416140,
  "title": "Telegram Desktop vulnerability allowed any user's file to be stolen",
  "url": "https://urgent.news/2026/10/10/telegram-desktop-vulnerability-allowed-any-users-file-to-be-stolen-13416140",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-10T03:02:47.000Z",
  "source": {
    "name": "Hacker News Best",
    "slug": "hacker-news-best",
    "url": "https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/"
  },
  "original_language": "en",
  "account": "A vulnerability in Telegram Desktop allowed any user's files to be stolen. When someone added a user to a Telegram group and sent a link in the chat, clicking the link gave the attacker access to the user's account. Telegram Desktop forwarded the clicked links to its own instance over a local socket, where they were never separated by a unique character. This allowed an injection attack, where a crafted link could read and send any file to a chat without checking the requester or requiring confirmation. The operating system registers URI schemes, so when Telegram Desktop registered tg., the system knew that tg:// links belonged to Telegram and launched them with the URL as a command-line argument. If Telegram was already running, the system launched a new process, which made it vulnerable to the same attack. The second defect was that the injected command reached an internal URI scheme, interpret:, which read a file named in an instruction file and sent it to a chat without a confirmation. An attacker could place an instruction file on the victim's disk and exfiltrate any file from their machine with a clicked link, exploiting the missing authorization check.",
  "summary": "Article URL: https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/ Comments URL: https://news.ycombinator.com/item?id=50029123 Points: 229 # Comments: 116",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Hacker News",
        "title": "Telegram Desktop vulnerability allowed any user's file to be stolen",
        "url": "https://urgent.news/2026/10/10/telegram-desktop-vulnerability-allowed-any-users-file-to-be-stolen",
        "published": "2026-10-10T03:02:47.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}