PoC Released for Telegram Desktop Flaw Enabling One-Click File Account Takeover
A public proof of concept has exposed a flaw in Telegram Desktop that could let attackers steal local files and take over accounts after a user clicks a crafted external link. Tracked as CVE-2026-107181, the vulnerability affects versions before 7.2.9 and carries a CVSS 4.0 severity rating of 8.6...