A Telegram Desktop flaw lets any user's files be stolen. Someone adds you to a group, you click a link, and your Telegram account is no longer only yours. Telegram Desktop hands clicked links to its already-running instance over a local socket as text, never escaping the semicolon used to separate commands. A crafted link becomes several instructions.
The chain has two defects: injection, and what the injected command reaches—an internal URI scheme, interpret:, that reads a file named in an instruction file and sends it to a chat without checking who asked for it or a confirmation. Together they turn a clicked link into arbitrary file read. CVE-2026-10718 is fixed in Telegram Desktop 7.2.9, commit db3405699f, with severity 8.1 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
Affected Telegram Desktop through 7.2.8, confirmed on Windows (6.9.3). Remote arbitrary local file read is exfiltrated to an attacker-controlled chat, enabling account takeover.
The bug lives in how Telegram serializes URLs over a local socket. Each instruction is a keyword, its argument, then a semicolon. A semicolon inside a transmitted value splits the instruction stream, letting a single clicked link become multiple commands.
Source: Hacker News · Summarized by HeadlinesBriefing