Critical Vulnerability in Telegram Desktop: File and Account Theft
A critical vulnerability has been discovered in the Telegram Desktop app for PC, allowing attackers to steal files from a user's computer with a single click.
The attack only requires the victim to click on a special link. After that, the hacker gains access to the files without any additional confirmations or permission requests.
The main target of the attack is tdata session files. Obtaining them allows an attacker to log into someone else's Telegram account without re-authentication. Other accessible documents may also be stolen.
The vulnerability affects Telegram Desktop versions below 7.2.9. Experts have rated the danger level of this bug at 8.6 out of 10 possible points.
To protect against this attack, you need to take the following actions:
- Update the Telegram Desktop app to version 7.2.9 or later
- Enable a local passcode in the security settings











