1 min read
Add as a preferred source on Google

Telegram Desktop Vulnerability Exposes Local Files Through Malicious Links

The flaw affects version 7.2.8 and earlier and was fixed in version 7.2.9, including an attack path involving Telegram session files.

Laptop beside a USB drive and scattered storage folders / TokenPost.ai
Laptop beside a USB drive and scattered storage folders / TokenPost.ai

A high-severity vulnerability in Telegram Desktop could let attackers steal local files and account-session data when users click malicious links, creating a security risk for crypto users who store sensitive information on their devices.

The flaw, identified as CVE-2026-107181, affects Telegram Desktop version 7.2.8 and earlier. A specially crafted tg:// link opened from a browser or another external app can trigger an interprocess communication injection that reads arbitrary local files and sends them to an attacker-controlled Telegram channel.

The exposed data may include Telegram’s tdata session files, which could allow an attacker to take over an account. The vulnerability was disclosed by security researcher Emiliano Versini.

Telegram fixed the issue in version 7.2.9. Crypto users commonly use Telegram for project communications, trading groups and community coordination, making local files such as wallet recovery information, private-key screenshots and transaction records potential targets if they are stored on an affected device.

Users should update Telegram Desktop to version 7.2.9 or later and avoid opening unknown links. Local password protection for Telegram sessions can provide an additional safeguard.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…