Security researcher BeakSec has disclosed a critical vulnerability (CVE-2026-107181) in Telegram Desktop that could allow attackers to hijack user accounts. The flaw affects version 7.2.8 and earlier, enabling threat actors to inject commands via inter-process communication by placing malicious files in group chats and luring victims to click browser-redirected links.
Successful exploitation allows attackers to exfiltrate local session files to a controlled group. If the victim has not set a local passcode, stolen session data can be used to fully compromise the account. Telegram released a fix for this vulnerability on September 17 in version 7.2.9, and users are advised to update immediately.
Critical Telegram Desktop Vulnerability Patched in Version 7.2.9
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
