Critical Vulnerability in Telegram Desktop: File Theft and Account Takeover
A critical vulnerability has been discovered in the Telegram Desktop client, allowing attackers to steal files from a user's computer with a single click. The attack does not require additional confirmations or interaction from the victim.
The tdata session files pose a particular threat as they contain login credentials for accounts. Attackers can gain full access to other users' messages without re-authentication.
Versions of Telegram Desktop below 7.2.9 are affected by this vulnerability. Security experts have rated the danger level of this bug at 8.6 out of 10.
To protect against this attack, you need to perform the following actions:
- Update the Telegram Desktop application to version 7.2.9 or later
- Enable the local code password in security settings









