Telegram Desktop: one-click account takeover via IPC injection

What happened
An unescaped separator in Telegram Desktop’s single-instance IPC lets one clicked link read arbitrary files off the disk and send them to the attacker, session files included.
Summary assembled by rule from the sources below