Capturing data…
Capturing data…
MON, 12 OCT · 83 ITEMS
"Telegram Desktop vulnerability allowed any user's file to be stolen" — Hacker News (best) · AI & Technology
A security researcher published a detailed write-up showing that Telegram Desktop (the native Windows/macOS/Linux client) had a flaw that could let an attacker, with a single click on a crafted message or link, run hidden JavaScript that steals local files and takes over the victim's Telegram account. The vulnerability is tracked as -2026-107181 and was fixed in Telegram Desktop version 7.2.9. The headline's 'any user's file' means any file the victim's user account can access on their own machine, not files on Telegram's servers.
The claim is based on a primary-source security disclosure with a public proof of concept, assigned CVE-2026-107181, and Telegram shipped a patch in 7.2.9 — so the core vulnerability and fix are solid. The 'any user's file' phrasing is a headline-level generalization of the researcher's finding; the researcher's own title emphasizes one-click , while subsequent coverage and the CVE description confirm local file theft. Scope details beyond the write-up should be read as reporting, not as the researcher's exact language.
This is a genuinely new disclosure from October 10, 2026, not resurfaced material.