Critical Telegram Desktop flaw lets tg:// links silently steal files from your PC

matthew_d_green · x · 2026-10-10

Researchers urge an immediate Telegram Desktop update: a critical vulnerability lets attackers gain account access and silently exfiltrate files.

The attack abuses tg:// protocol links: a crafted command makes clicking the link trigger a malicious script that sends a chosen file to the attacker's channel, with no extra confirmation required.

Original post →

More from Safety

Safety channel →