A security researcher has disclosed a Telegram Desktop vulnerability chain that could let an attacker steal files from a computer after persuading a user to click a specially prepared Telegram link. The reported chain combined weak parsing in Telegram's communication between app instances with an internal file-sending function that lacked an authorization check.
The researcher found the issue in the desktop client's handling of its `tg:` links. When Telegram is already open and the operating system launches another instance for a link, the new process passes the link to the running process through a local socket. Telegram serialized those instructions as text separated by semicolons, but did not safely escape a semicolon embedded in the supplied value. The running instance could consequently interpret one incoming link as more than one instruction.
That parsing problem became more serious because the receiving process accepted an `OPEN:` instruction for schemes beyond the public Telegram protocol. One reachable internal scheme, `interpret:`, was designed for Telegram's own release workflow. It could read a small instruction file and send a nominated local file to a channel or supergroup. According to the research, this function neither confirmed the action with the user nor verified who initiated it.
An attacker would still need to put a predictable instruction file on the target computer. The researcher said Telegram's automatic download behavior for files received in groups supplied that step: a small attachment could be saved under a known name in a standard download location. The crafted link could then refer to that instruction file through a relative path. Once processed, the instruction could direct Telegram to upload another local file to a destination controlled by the attacker.
The demonstration targeted Telegram session files, which are especially sensitive because they can allow another party to act through an authenticated account. The underlying capability was broader, however, because the internal function could be pointed at other files readable by the Telegram process.
The report is a reminder that local inter-process channels need the same strict input boundaries as internet-facing interfaces. A value that is valid as a URL can become dangerous if it is flattened into a delimiter-based command format and reconstructed without escaping. Privileged internal features also require explicit authorization when any externally influenced path can reach them.
Users should treat unexpected links and attachments as potentially connected parts of one attack rather than isolated messages, and should install Telegram Desktop security updates as they become available. The supplied evidence documents the researcher's technical findings; it does not independently establish the affected version range or remediation status.


