Telegram Desktop vulnerability allowed any user's file to be stolen

246 points · 128 comments on HN · read original →

Points and comments are a snapshot, not live.

A crafted link in Telegram Desktop could steal any user file and take over their account.

Telegram Desktop through version 7.2.8 had a vulnerability allowing one-click arbitrary file read and account takeover. The flaw was two-fold: first, a semicolon in a `tg://` link was not escaped when sent over a local socket to an already-running instance, allowing command injection. Second, an internal `interpret:` URI scheme, originally for publishing releases, read any local file and sent it to a chat without authorization checks. An attacker could deliver the malicious link via a redirect from an ordinary `https` link. Three instruction files dropped in a group chat would exfiltrate `key_datas`, the MTProto authorization file, and the account index. With no local passcode set, the stolen files allowed session decryption. Fixed in 7.2.9.

What commenters are saying

Commenters noted this is not the first security issue Telegram has had, citing its history of protocol and infrastructure concerns. Some defended Telegram's popularity on UX grounds despite known flaws. A split emerged: while the vulnerability is severe, several commenters argued that the real underlying issue is that desktop operating systems do not sufficiently sandbox user processes from each other's files. Others pointed out that Telegram could choose to sandbox itself on desktop but has not. The thread included references to past Telegram vulnerabilities, such as Filippo Valsorda's analysis of an ECDH bug.