Telegram Desktop has a vulnerability, CVE-2026-107181: one click on a link is enough to send files from your computer to an attacker. That includes the tdata folder with session keys, which let someone open your Telegram account on another device. Every version up to and including 7.2.8 is affected; the fix shipped in 7.2.9. Here is how the attack works, who is at risk and what to do right now.
In short: what happened
- What: a flaw in the official Telegram client for computers. Severity is 8.6 out of 10 on CVSS 4.0 and 8.1 on CVSS 3.1, rated High.
- Who is affected: anyone running Telegram Desktop 7.2.8 or older.
- What can leak: local files from the disk, including Telegram session data from the tdata folder.
- What to do: update Telegram Desktop to 7.2.9 or newer.
- Who found it: researcher Emiliano Versini (BeakSec). His technical write-up was published on October 3 and updated on October 7, 2026.
How the Telegram Desktop attack works
The scenario BeakSec describes looks ordinary: someone adds you to a group, a link appears in the chat, you click it. Everything after that happens without you.
- Delivering the instructions. The attacker adds the victim to a group and posts an instruction file there. According to BeakSec, with default settings Telegram Desktop saves group attachments of up to 8 MiB automatically, so nothing has to be downloaded by hand. In channels this auto-download is off by default.
- The click. The victim opens a normal-looking HTTPS link. The browser redirects it to a
tg://address that launches Telegram. The browser may ask whether to open the app, but that is not consent to send files. - Command injection. Telegram Desktop passes the link to its already running instance over an internal channel and does not escape the character it uses to separate commands, the semicolon. So the app receives several commands instead of one.
- Sending the files. The injected command reaches an internal
interpret:handler. It reads the file named in the instructions and sends it to the attacker's chat with no check and no confirmation.
No "Send" dialog appears: the files simply leave.
What can be stolen: tdata, passwords and keys
The main target in the demo is the tdata folder, where Telegram Desktop keeps its login data. Whoever gets these files can open your account on their own computer, with no SMS code and no cloud password, because the session is already authorized.
According to BeakSec, if no local passcode is set, the session can be restored from the stolen files on another device. A passcode makes that harder but does not stop the files from leaking.
Account takeover is only the example that was shown. The researcher also lists SSH keys, browser password stores and files with API tokens as possible targets.
Affected versions and the fix timeline
- Affected: Telegram Desktop up to and including 7.2.8. According to BeakSec, exploitation was confirmed on Windows.
- September 17, 2026: version 7.2.9 was released with the fix. The GitHub release notes contain a single line about animation rendering and do not mention the vulnerability.
- October 3: BeakSec published the write-up. October 7: the flaw was assigned CVE-2026-107181.
The CVE description names only Telegram Desktop, the client for computers. Mobile apps and the web version are not mentioned there.
How to check your version and update Telegram Desktop
- Open the menu (three lines in the top left). The version number is at the bottom of the menu.
- If it says 7.2.8 or older, go to Settings → Advanced → Version and updates and click "Check for updates".
- If Telegram came from the Microsoft Store, Mac App Store, Snap, Flatpak or a Linux repository, update it there.
- Portable builds (a folder with Telegram.exe and tdata) may not update on their own. Download the latest version from the official site, desktop.telegram.org, and replace the executable.
- Restart the app and make sure the version is 7.2.9 or newer.
Extra steps to protect your account
- Set a local passcode: Settings → Privacy and Security → Local passcode. It makes a stolen session harder to use.
- Review active sessions: Settings → Devices. Terminate any you do not recognize.
- Limit group invites: Settings → Privacy and Security → Groups and channels → "My contacts".
- Turn off automatic file download in groups: Settings → Advanced → Automatic media download.
- Do not keep passwords, seed phrases or tokens in plain text files on a work computer.
These limits only reduce the risk. One action closes the vulnerability: updating to 7.2.9 or newer.
What this means for media buyers and affiliates
For a regular user this is a risk of losing chats. For a media buyer or a team it is a risk of losing working infrastructure.
- Purchased tdata accounts. They are often run in a portable Telegram Desktop of whatever version the seller put in the archive, and those builds can be old. If you handle accounts in bulk, check the version in every folder.
- Channels, bots and chats. Whoever gets into the owner's account gets the owner's rights: channels, bots and working chats with affiliate networks. For anyone running Telegram traffic, that is money on the line.
- Credentials on disk. It is not only Telegram: files with ad account passwords, tracker and service tokens, and server keys are exposed if they sit on the same computer.
- Team work. One buyer's outdated computer opens the whole team's shared chats. Ask everyone to update, and do not open links in groups you were added to without asking.
FAQ
What is CVE-2026-107181?
It is the identifier of a vulnerability in Telegram Desktop before 7.2.9. A crafted tg:// link makes the app send local files, including tdata session data, to the attacker's chat. It is rated 8.6 on CVSS 4.0.
Does the victim have to click anything?
Yes, once: the link. No confirmation is needed to send the files after that.
Are Telegram mobile apps and Telegram Web affected?
The vulnerability description names only Telegram Desktop, the app for computers. Mobile clients and the web version are not mentioned.
Does two-step verification help?
Not against this attack. The cloud password protects a new login by phone number, while here an already authorized session is stolen. Updating and a local passcode are what help.
How do I know if my account was already compromised?
Open Settings → Devices. If you see an unfamiliar device, terminate its session, change your cloud password and replace the passwords and keys that were stored on the computer.
Does the update fully fix the problem?
According to BeakSec and the CVE description, the flaw is fixed in version 7.2.9. All earlier versions are considered vulnerable.
Sources: BeakSec write-up, VulnCheck, Telegram Desktop 7.2.9 release on GitHub.



