logoalt Hacker News

Telegram Desktop vulnerability allowed any user's file to be stolen

107 points • by g-b-r • today at 3:02 AM • 46 comments • view on HN

Comments

usr1106 • today at 6:18 AM

I don't use Telegram Desktop or Windows. But that's exactly the reason why I run Firefox in a firejail sandbox on Linux. The browser has only access to my Downloads folder. I know that it's considered untrusted and don't keep any files there for a long time.

➕ show 4 replies
Panzerschrek • today at 5:21 AM

It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file. Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory (like downloads for a browser or Telegram-client).

➕ show 8 replies
erelong • today at 4:49 AM

I thought telegram was flagged as insecure like a decade ago, it's never really been "very secure"

Like any number of articles like this: https://hackernoon.com/7-reason-why-telegram-is-insecure-by-...

➕ show 4 replies
opengrass • today at 5:30 AM

doas jexec -U opengrass tellyjail env DISPLAY=:0 Telegram

➕ show 1 reply
g-b-r • today at 3:02 AM

This link has already been posted with https://news.ycombinator.com/item?id=50019667 , but that post's title ("Telegram Desktop: one-click account takeover") doesn't say that the vulnerability allowed also any user-accessible file on the disk to be stolen.

This aspect is also not highlighted much in the article, which weirdly mostly focuses on the account takeover.

To me it seems something remarkable enough to warrant reposting the link with a different title.

Somewhat astonishingly, the core of the vulnerability comes from an internal url scheme added to Telegram to... help them publish their releases on their channel.

The Telegram developers saw no better way to do that than adding an internal tool which uploads any file it's told to.

Everyone else publishing their app on Telegram is able to do that with a script, but they had to do it that way.

It's true that it was exploitable only in a somewhat convoluted way, but still, it's an obviously dangerous feature.

Anyhow, yes, clicking on a link in Telegram Desktop was enough to have any user's file exfiltrated and to access or take over their account.

➕ show 1 reply
anon_cow1111 • today at 6:09 AM

Imagine if you forgot to update your phone number with your personal bank, and then some random guy was given full access to your account and all of its contents. And even if you dug through the account options and set a 2FA password (normally disabled) he could still just delete your account outright.

Last I checked, that's exactly how Telegram works by default. It's laughable to consider a service tied to a phone number secure.

➕ show 1 reply
KingOfCoders • today at 5:07 AM

It's not a bug it's a feature.

➕ show 1 reply
colordrops • today at 7:12 AM

well duh

bashtoni • today at 6:39 AM

Russian social media app has backdoor. Who would have thought?

(Yes, I know they're technically Dubai based now)

➕ show 1 reply
seeknotfind • today at 7:02 AM

Wow, that's pretty bad, but imagine if 50% of software allowed this to happen at any time, and it was discovered on December 1st, 2026. What would happen?

➕ show 1 reply