A high-severity security vulnerability in Telegram Desktop could allow attackers to hijack user accounts and steal local files by tricking victims into clicking a specially crafted link. The flaw, tracked as CVE-2026-10718, affects versions released before Telegram Desktop 7.2.9, according to security researcher BeakSEK.
The vulnerability stems from how the desktop application handles certain characters in links. In vulnerable versions, semicolons are not properly escaped in specially crafted Telegram links, allowing attackers to inject additional commands that the application may interpret as legitimate instructions.
“Someone adds you to a Telegram group. A link shows up in the chat. You click it, and your Telegram account is no longer only yours,” BeakSEK warned while explaining the issue in a technical write-up published on GitHub.
The most serious part of the vulnerability involves Telegram Desktop’s internal interpret: scheme handler. According to the researcher and the National Vulnerability Database, attackers could abuse this functionality to read local files and send them to a Telegram chat without asking the victim for confirmation.
The internal feature was designed for trusted operations, but the reported flaw meant the application did not adequately verify who was requesting the action. An attacker who successfully exploits the vulnerability could potentially steal Telegram session data, including files associated with the application’s local encryption keys and account authorization.
The vulnerability has been assigned a CVSS severity score of 8.6 out of 10, placing it in the high-severity category.
BeakSEK demonstrated a potential attack scenario in which a malicious actor creates a Telegram supergroup and adds unsuspecting users. The attacker then distributes several specially prepared text files and posts a link that appears harmless but contains a malicious Telegram command.
In its default configuration, Telegram Desktop can automatically download certain files received in group chats, subject to its download settings and file-size limits. The researcher’s proof of concept uses this behavior alongside a crafted link to demonstrate how the attack could work.
If a victim clicks the malicious link while running a vulnerable version of the application, the injected commands could trigger unauthorized file access and transmit sensitive data to an attacker-controlled chat. The stolen session information could then potentially be used to restore the victim’s Telegram session on another installation, particularly if additional local security protections are absent.
The demonstrated attack relies on several conditions, including the vulnerable application version, the victim opening the crafted link, and the attacker preparing the required files and commands. Users should therefore distinguish the reported proof of concept from a claim that every Telegram account can be compromised simply by receiving a message.
To reduce the risk, users should update Telegram Desktop to version 7.2.9 or later, preferably the latest available release. The supplied report states that Telegram Desktop version 7.3 was released on October 9, 2026, although users should verify the latest version through Telegram’s official update channels.
Users should also review their group privacy settings to restrict who can add them to groups, enable a local application passcode, and turn on the option to ask where each downloaded file should be saved. These measures can reduce exposure, but updating to a patched version is the primary defense against this vulnerability.
The incident highlights how a seemingly ordinary link in a trusted messaging application can become a security risk when the software mishandles commands or grants internal features excessive privileges.



