Telegram Desktop vulnerability allowed any user's file to be stolen
g-b-r
46 points
13 comments
October 10, 2026
Related Discussions
Found 5 related stories in 143.2ms across 8,999 title embeddings via pgvector HNSW
- Trezor's email provider has been breached andreyazimov · 15 pts · September 09, 2026 · 52% similar
- Cyberstalkers Are Exploiting Chrome Sync to Spy on Victims hn_acker · 17 pts · July 14, 2026 · 50% similar
- Dropbox Got Hacked yonilevy · 34 pts · August 31, 2026 · 49% similar
- Dropbox Data Breach hmate9 · 24 pts · August 31, 2026 · 49% similar
- Chrome adopts what may be the best protection yet against account takeovers joozio · 13 pts · August 12, 2026 · 49% similar
Discussion Highlights (5 comments)
g-b-r
This link has already been posted with https://news.ycombinator.com/item?id=50019667 , but that post's title ("Telegram Desktop: one-click account takeover") doesn't say that the vulnerability allowed also any user-accessible file on the disk to be stolen. This aspect is also not highlighted much in the article, which weirdly mostly focuses on the account takeover. To me it seems something remarkable enough to warrant reposting the link with a different title. Somewhat astonishingly, the core of the vulnerability comes from an internal url scheme added to Telegram to... help them publish their releases on their channel. The Telegram developers saw no better way to do that than adding an internal tool which uploads any file it's told to. Everyone else publishing their app on Telegram is able to do that with a script, but they had to do it that way. It's true that it was exploitable only in a somewhat convoluted way, but still, it's an obviously dangerous feature. Anyhow, yes, clicking on a link in Telegram Desktop was enough to have any user's file exfiltrated and to access or take over their account.
erelong
I thought telegram was flagged as insecure like a decade ago, it's never really been "very secure" Like any number of articles like this: https://hackernoon.com/7-reason-why-telegram-is-insecure-by-...
KingOfCoders
It's not a bug it's a feature.
Panzerschrek
It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file. Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory (like downloads for a browser or Telegram-client).
opengrass
doas jexec -U opengrass tellyjail env DISPLAY=:0 Telegram