← 返回事件
持续讨论科技收购

Telegram Desktop: one-click account takeover via IPC injection

图:Lobsters

发生了什么

An unescaped separator in Telegram Desktop’s single-instance IPC lets one clicked link read arbitrary files off the disk and send them to the attacker, session files included.

摘要按规则整理自下方来源原文

为什么在扩散

来源