DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Telegram Desktop: one-click account takeover via IPC injection

Quality: 9/10 Relevance: 9/10

Summary

BeakSec details a Telegram Desktop vulnerability (CVE-2026-107181) allowing one-click account takeover via IPC injection. The bug exploited an unescaped separator in the single-instance IPC and an interpret: URI to read local files and exfiltrate session data; fixed in version 7.2.9 with the removal of interpret: and improved encoding. Practical mitigations include upgrading, enabling per-file save prompts, limiting group invites, and using a local passcode.

🚀 Service construit par Johan Denoyer