律动BlockBeats
律动BlockBeats|Oct 09, 2026 11:40
[High-Risk Vulnerability in Telegram Desktop: Clicking Malicious Links Can Instantly Steal Local Files and Sessions, Encrypted Community Users Urged to Update Immediately] BlockBeats News, October 9 – Security researcher beaksec (Emiliano Versini) recently disclosed a high-risk vulnerability (CVE-2026-107181) in Telegram Desktop, affecting version 7.2.8 and earlier. Attackers can craft malicious tg:// links, and when users click them externally (e.g., in a browser), they can exploit IPC injection to read any local files (including tdata session files) and send them to the attacker’s channel, potentially leading to account takeover. This vulnerability has been patched in version 7.2.9. Given that many cryptocurrency projects, communities, and trading groups rely heavily on Telegram, sensitive information such as wallet seed phrases, private key screenshots, and transaction records are often stored locally. Users are strongly advised to immediately check and update Telegram Desktop to the latest version, avoid clicking on unknown links, and enable local password protection for sessions to reduce the risk of theft. [Original Link]
+3
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads