Cybersecurity alert about a Telegram Desktop flaw that could steal files and hijack an account through a malicious link

Telegram Desktop Flaw: a Simple Link Could Be Enough to Hack Your Account

October 11, 2026 Off by Password Revelator

This article will also interest you: Look Up: These Sites That Resell Your Stolen Data

A critical vulnerability affected Telegram Desktop, the computer version of the messaging app. According to research by cybersecurity researcher BeakSec, a trapped link could trigger the theft of files stored on the machine and, in some cases, make it possible to take over a Telegram account without knowing the password.

The flaw, tracked as CVE-2026-107181, was fixed in Telegram Desktop 7.2.9, released on September 17, 2026. Its severity score reached 8.1 out of 10, a high level.

Telegram Desktop: a critical flaw in a few figures

Item Information
Reference CVE-2026-107181
Affected software Telegram Desktop
Severity 8.1 / 10
Fixed version 7.2.9
Patch deployed September 16, 2026
Version released September 17, 2026
Public details October 3, 2026
Last update October 7, 2026

This vulnerability affected Telegram Desktop only, not every version of Telegram. Users who had not installed the update could remain exposed.

How could a single click compromise a Telegram account?

The scenario relied on a particularly discreet trick.

An attacker could:

  • add the victim to a Telegram group;
  • place certain files in that group;
  • share a link that looked harmless.

If the victim clicked that link, the Telegram app installed on their computer could carry out an unexpected action. By combining two security flaws, the attacker could cause files stored on the computer to be sent automatically to a group they controlled.

Important point: Telegram did not always ask the user to confirm the send. The victim could therefore believe they were simply opening a link, while sensitive data could be transmitted without their knowledge.

The attack still required several conditions:

  • a vulnerable version of Telegram Desktop;
  • a link specially prepared by the attacker;
  • the victim interacting with that link.

Why was this flaw so dangerous?

The risk was not limited to sending a few files.

Telegram Desktop stores files locally that keep the session open. Those files spare the user from signing in again every time the app starts.

Researcher BeakSec showed that an attacker could, under certain conditions, recover those files and rebuild a Telegram session on another machine. They could then access the victim's account without knowing the password.

The danger was even higher when the user had not enabled a local lock code in Telegram Desktop. That code did not fix the flaw, but it made the recovered session files harder to exploit.

Other files could also be exposed

Beyond the Telegram account, the vulnerability could make it possible to read and transmit other files accessible from the computer.

The researcher mentions in particular:

  • sensitive documents;
  • access keys;
  • files containing login details for other services.

The consequences could therefore go beyond the messaging app alone.

Note: this research shows that an attack was technically possible. It does not prove that every Telegram account was hacked, nor how many people were actually affected.

Telegram fixed the flaw in September 2026

The timeline published by the researcher traces the steps:

  • June 25, 2026: the vulnerability was reported through the Zero Day Initiative (ZDI) program;
  • September 16, 2026: Telegram applied a patch;
  • September 17, 2026: Telegram Desktop 7.2.9 was released;
  • October 3, 2026: technical details were published;
  • October 7, 2026: the identifier CVE-2026-107181 was officially assigned.

The update removes, among other things, an old internal function used to send files. It also corrects the way the app handles certain instructions.

The patch was rolled out quietly: the release notes did not explicitly mention this vulnerability.

How can you protect your Telegram account?

The most important step is still the update.

1. Install Telegram Desktop 7.2.9 or a newer version

This is the version that actually fixes the flaw. If you are using an earlier version, update the app without delay.

2. Limit who can add you to groups

In the privacy settings, you can restrict group invitations. That reduces the risk of being added to a group controlled by an attacker.

3. Turn on a local lock code

This code does not fix the vulnerability, but it makes recovered session files harder to exploit.

4. Stay alert to unexpected links

Even inside a Telegram conversation, a link can be trapped. Do not click a link received from a doubtful source or without clear context.

5. Check your active sessions

Review the devices connected to your Telegram account. Sign out of any session you do not recognize.

6. Strengthen the security of your other accounts

If you think sensitive files may have been exposed, change the related passwords and turn on two-factor authentication.

FAQ: common questions about the Telegram Desktop flaw

Was Telegram hacked on a massive scale?

No. The published research shows that an attack was technically possible, but it does not establish how many people were actually affected.

Is my version of Telegram Desktop vulnerable?

If your version is older than 7.2.9, it may be exposed. Check the installed version and update if needed.

Is a local lock code enough to stay protected?

No. It makes exploitation harder, but it does not replace the patch. Updating to 7.2.9 remains essential.

What should I do if I think I was affected?

Update Telegram Desktop, change your Telegram password, revoke active sessions you do not recognize, turn on two-factor authentication, check files and messages sent without your knowledge, and report any suspicious behavior.

Is the flaw still active?

No. It was fixed in Telegram Desktop 7.2.9 and later versions.

What to remember

  • A critical flaw affected Telegram Desktop, tracked as CVE-2026-107181.
  • A single click on a trapped link could trigger the sending of local files and, under certain conditions, allow an account takeover.
  • The flaw received a severity score of 8.1 out of 10.
  • Telegram published a fix in version 7.2.9 on September 17, 2026.
  • Users should update the app, restrict group invitations and turn on a local lock code.
  • There is no evidence that every Telegram account was compromised.

The update remains the most effective protection. If you are still using an earlier version of Telegram Desktop, install version 7.2.9 or a newer release now.