Topic
Everything filed under Vulnerability Research, newest first.
RSS · JSON · All topics
Telegram Desktop: one-click account takeover via IPC injection
A BeakSec writeup of CVE-2026-107181: an unescaped separator in Telegram Desktop's single-instance IPC let a single clicked link inject commands that reach the internal interpret: scheme, read arbitrary local files such as session files, and send them to an attacker's chat. Fixed quietly in 7.2.9.
12 min · 2,810 words