PoC Released for Telegram Desktop Flaw Enabling One-Click File Account Takeover
A Proof of Concept (PoC) is available for CVE-2026-107181, a high-severity vulnerability in Telegram Desktop versions prior to 7.2.9, allowing attackers to steal local files and potentially take over accounts.

A public proof of concept has exposed a flaw in Telegram Desktop that could let attackers steal local files and take over accounts after a user clicks a crafted external link. Tracked as CVE-2026-107181, the vulnerability affects versions before 7.2.9 and carries a CVSS 4.0 severity rating of 8.6 (High). Researcher Beaksec published the technical write-up on October 3, 2026, and updated it on October 7. VulnCheck assigned the CVE that day.
The reported attack reaches Telegram’s local session data, making account takeover possible when the victim has not enabled a local passcode. The weakness lies in how Telegram Desktop handles links opened outside the app. When Telegram is already running, another instance passes the link to it through a local communication channel, known as inter-process communication, or IPC. That channel failed to escape a character used to separate records.
An attacker could place the character inside a crafted link and make Telegram read part of the link as another command. The CVE record classifies this as CWE-143, improper handling of record delimiters. According to ThreatWire’s research, the injected command could access an outdated internal helper designed for release publishing. The helper could read local files and send them to a chat without permission checks or user confirmation, resulting in file theft through Telegram itself.
Stolen session files could let an attacker reuse the victim’s logged-in account. Earlier reporting on Telegram account hijacking through voicemail shows another route to account loss, but that method is separate from this Desktop vulnerability. The researcher demonstrated the chain on Windows using Telegram Desktop 6.9.3 and reported that it remained present through 7.2.8. Although the CVE covers Telegram Desktop generally, the write-up does not demonstrate the attack on macOS or Linux.
The link must be opened outside Telegram, such as from a browser. Links clicked inside Telegram follow a different processing path and are not affected. A browser may also ask for permission before launching the desktop app. The demonstrated chain depends on automatic group file downloads and settings that allow anyone to add the victim to a group. These conditions matter when judging the “one-click” claim.
Telegram fixed the issue in commit db3405699f on September 16 and released version 7.2.9 on September 17. The reported changes remove the legacy helper, escape the record separator, and strengthen handling of mixed record types. The release notes mention only a rendering fix, not the security issue. No vendor security advisory is identified in the supplied reporting.
The CVSS 3.1 score is 8.1, while CVSS 4.0 gives 8.6. Both ratings describe the same flaw. Users should update every Telegram Desktop installation to 7.2.9 or later. Until then, restrict group invitations, stop automatic downloads, and enable a local passcode. Treat unexpected browser prompts to open Telegram cautiously.
As of October 9, the supplied reporting identifies no known exploitation or CISA KEV listing. A public PoC demonstrates feasibility, not confirmed attacks. The public write-up should not be mistaken for independent attack confirmation. Users who suspect exposure should end other active sessions and review chats for unexpected file uploads.