Critical Telegram Desktop bug: hackers can steal accounts with a single click
Telegram stumbles on semicolons.

Image by Cybernews.
- Telegram Desktop before version 7.2.9 mishandles crafted links, allowing attackers to run hidden commands.
- A victim may lose account access after clicking one malicious link in a Telegram group.
- Attackers can steal session files and restore the victim’s Telegram account on another device.
- Users should update Telegram Desktop, restrict group invites, set a local passcode, and stop automatic downloads.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Hackers can exploit the Telegram Desktop vulnerability to hijack accounts and exfiltrate user files with just a single click.
A severe vulnerability has been discovered in Telegram Desktop before version 7.2.9, which was released on September 17th, 2026.
“Someone adds you to a Telegram group. A link shows up in the chat. You click it, and your Telegram account is no longer only yours,” said a security researcher who goes by the alias BeakSEK.
The researcher explains on GitHub that vulnerable versions of the Telegram Desktop application don’t properly handle certain characters in links – fail to escape semicolons. Telegram itself uses the semicolon character (;) to separate instructions.
Hackers can exploit this to add malicious commands in a crafted tg:// links. For example, a hacker can send a link with malicious commands separated by semicolons, and the application treats them as legitimate commands.
The second defect is what the injected command reaches.
Only 4 commands are available to attackers, and 3 of them are harmless.
“Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover,” the description on the NIST’s National Vulnerability Database reads.
The interpret: internal feature can perform a privileged action – to read any file on disk and send it to chat, without asking for any confirmation.
This tool was designed for trusted internal use by Telegram's developers, but it didn’t verify who requested the action.
The bug is rated 8.6 out of 10 on the CVSS severity scale, and has been assigned CVE-2026-10718.
The latest Telegram version is 7.3, which was released on October 9th with only one word in the release notes: “Money.”
What could an actual attack look like?
The researcher detailed a proof of concept in which an attacker creates a supergroup on Telegram and adds victims, which Telegram’s default privacy settings allow.
In the group, the attacker posts 3 crafted instruction .txt files, and Telegram automatically downloads them to the victim’s machines.
Telegram Desktop in its default configuration downloads files received in groups up to 8 MiB (mebibyte) automatically,the researcher explains.
The hacker then posts a link that may appear innocuous – it redirects to a malicious tg: link containing injected commands.
If a victim clicks it, their system will launch a second Telegram process, and the command execution will fire. The Telegram app will leak files that allow the hacker to recover the session and the victim’s account.
The 3 instruction files specify what files to exfiltrate: local encryption key, session authorization data, and the index of the account’s stored data. Relative paths allow locating destinations without knowing the victim’s Windows username.
An attacker can then simply drop the stolen files into a fresh Telegram instance and restore the victim’s session, assuming no local passcode was set.
BeakSec urges users to update Telegram Desktop apps to the latest available version and limit who can add them to groups. The researcher also recommends setting a local passcode and turning on “ask where to save each file” – it stops automatic file downloads.