Telegram Desktop: one-click account takeover via IPC injection

发生了什么
An unescaped separator in Telegram Desktop’s single-instance IPC lets one clicked link read arbitrary files off the disk and send them to the attacker, session files included.
摘要按规则整理自下方来源原文