Post cover image
From a clicked link to the victim's session files.

October 10, 2026

Telegram Desktop: one-click account takeover via IPC injection

An unescaped separator in Telegram Desktop’s single-instance IPC lets one clicked link read arbitrary files off the disk and send them to…

By cyber security

10 min read