Security researcher BeakSec said Telegram Desktop previously carried a high-severity vulnerability tracked as CVE-2026-107181. According to the disclosure cited by ChainCatcher, an attacker could place a command file in a group where the victim was present, then trick the victim into clicking a browser-redirected link. The exploit used inter-process communication command injection to send local files to a group controlled by the attacker. BeakSec added that if session files were stolen and the user had not set a local password, the account could also be taken over. The researcher said versions 7.2.8 and earlier were affected, and the issue was fixed in version 7.2.9 released on Sept. 17.
ChainCatcher reported that security researcher BeakSec disclosed a high-severity vulnerability in Telegram Desktop, tracked as CVE-2026-107181.
According to the disclosed details, an attacker could first place a command file in a group that included the victim, then lure the victim into clicking a browser-redirected link. The flaw could then be used through inter-process communication command injection to send local files to a group controlled by the attacker.
If session files were stolen and the user had not enabled a local password, the account could also be taken over.
BeakSec said versions 7.2.8 and earlier were affected. The vulnerability was fixed in version 7.2.9 released on Sept. 17.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.