Critical Telegram Desktop flaw lets tg:// links silently steal files from your PC
matthew_d_green · x · 2026-10-10
Researchers urge an immediate Telegram Desktop update: a critical vulnerability lets attackers gain account access and silently exfiltrate files.
The attack abuses tg:// protocol links: a crafted command makes clicking the link trigger a malicious script that sends a chosen file to the attacker's channel, with no extra confirmation required.
More from Safety
- Bengio boosts AI slowdown call: Claude now leads 26% of Anthropic R&D, RSI red line 'has become the plan' — Yoshua_Bengio · 2026-10-10
- NULLs wins COLM Privacy & Security Workshop Best Paper for natively unlearnable LLMs — AdtRaghunathan · 2026-10-10
- Cosmos Institute founder warns AI 'pacing' regulators would gain near-unlimited power — luke_drago_ · 2026-10-10
- Phantom Transfer: data poisoning survives 11 data-level defenses, NeurIPS 2026 paper shows — OwainEvans_UK · 2026-10-10
- Polymarket puts 13% odds on a US AI safety bill by end of 2026 — Polymarket · 2026-10-10
- Google opens SynthID Detector to everyone, 180B images and videos already watermarked — shashib · 2026-10-10