A critical flaw in Telegram Desktop let an attacker take over an account with a single click, and the proof-of-concept exploit is now public.
Tracked as CVE-2026-107181 and rated 8.6 (high) under CVSS v4, the bug sits in the way the desktop client hands clicked links to an already-running instance over a local socket. Telegram Desktop never escaped the character it uses to separate commands, so a crafted link containing an unescaped semicolon could be split into several instructions.
The injected instruction used an internal URI scheme called 'interpret:', which reads local files and sends them to a chosen chat without asking the user. Chained together, researchers said, the two behaviours turn 'a clicked link into arbitrary file read'. By first sending a disguised file that the client downloads to a predictable folder, an attacker could have the app upload a victim's session keys and then import them elsewhere to clone the session — a route that sidesteps two-factor authentication entirely.
Researchers at BeakSec published a full technical breakdown and exploit code; no active exploitation has been confirmed. The flaw affects Telegram Desktop before 7.2.9 and was verified on Windows. Telegram patched it in 7.2.9 by removing the 'interpret:' scheme and escaping record separators.
Users who cannot update immediately are advised to enable 'ask where to save each file', restrict who can add them to groups, and set a desktop passcode, which encrypts local session data. With more than 900 million Telegram users and a large desktop base, the patch is the only fully effective mitigation.




