Tech article

Telegram Desktop vulnerability allowed any user's file to be stolen

No preview is available. Read the original article for the full story.

Hacker News | Oct 10, 2026 | g-b-r

Automated excerpt

IntroductionSomeone adds you to a Telegram group. Together they turn a clicked link into arbitrary file read. So a path like this one:1 gives the attacker a deterministic path without ever needing the user name. From file read to account takeoverInterpretSendPath sends exactly one file per invocation: if an instruction file holds several file: lines, only the last one counts.

Selected automatically from source text; not independently written or fact-checked. Read the original for full context.

Read the original article

Read next

AI briefing: recent picks

More stories to explore