AI analysis
Telegram Desktop versions before 7.2.9 contain an IPC record-separator injection flaw in Core::Sandbox. A remote attacker can send a crafted tg:// link that includes unescaped semicolons so that, if the user opens it, injected OPEN: records reach the interpret: scheme handler. That path can upload local files, including tdata session keys, to an attacker-controlled channel and thereby take over the account. The issue affects users of Telegram Desktop older than 7.2.9 and requires the victim to interact with the malicious link. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Upgrade Telegram Desktop to version 7.2.9 or later on every machine that runs it. Until then, do not open tg:// links from untrusted chats, websites, or messages. If a suspicious link may already have been opened, log out other sessions from a trusted device, revoke active sessions, and treat local tdata session data as potentially exposed.
Affected
| Telegram Desktop | before 7.2.9 |
Estimated exposure
masstens of millions of Telegram Desktop installations (order-of-magnitude estimate) — Telegram publicly reports on the order of hundreds of millions of monthly users; the official desktop client is a widely distributed subset of that base, so affected installations are plausibly in the tens of millions, though Telegram does…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.