Telegram Desktop: one-click account takeover via IPC injection
Summary
BeakSec details a Telegram Desktop vulnerability (CVE-2026-107181) allowing one-click account takeover via IPC injection. The bug exploited an unescaped separator in the single-instance IPC and an interpret: URI to read local files and exfiltrate session data; fixed in version 7.2.9 with the removal of interpret: and improved encoding. Practical mitigations include upgrading, enabling per-file save prompts, limiting group invites, and using a local passcode.