Telegram Desktop high-risk vulnerability can lead to account takeover: version 7.2.9 has been fixed
According to security researcher BeakSec, Telegram Desktop previously had a high-risk vulnerability CVE-2026-107181. Attackers could pre-place command files in the group where the victim is located, then induce them to click on links redirected through the browser, using inter-process communication command injection to send local files to a group controlled by the attacker; if the session file is stolen and the user has not set a local password, the account may be taken over.The researcher stated that versions 7.2.8 and earlier are affected, and the vulnerability has been fixed in version 7.2.9 released on September 17.