Telegram Desktop high-risk vulnerability can lead to account takeover: version 7.2.9 has been fixed
According to security researcher BeakSec, Telegram Desktop previously had a high-risk vulnerability CVE-2026-107181. Attackers could pre-place command files in the group where the victim is located, then induce them to click on links redirected through the browser, using inter-process communication command injection to send local files to a group controlled by the attacker; if the session file is stolen and the user has not set a local password, the account may be taken over.
The researcher stated that versions 7.2.8 and earlier are affected, and the vulnerability has been fixed in version 7.2.9 released on September 17.
Related tags






