negativeSYS.SOURCE: beaksec• 2026-10-10T03:02:47Z
Telegram Desktop IPC Injection Vulnerability Enables Arbitrary File Read and Account Takeover
A vulnerability in Telegram Desktop's IPC injection mechanism allows arbitrary local file reads through unescaped separators, enabling session file exfiltration. The exploit leverages the interpret: URI scheme to bypass authorization checks and steal user data.
*** END OF TRANSMISSION ***