← Back to events
ActiveTechAcquisition

Telegram Desktop: one-click account takeover via IPC injection

Photo: Lobsters

What happened

An unescaped separator in Telegram Desktop’s single-instance IPC lets one clicked link read arbitrary files off the disk and send them to the attacker, session files included.

Summary assembled by rule from the sources below

Why it's spreading

Sources