Tech article
Telegram Desktop vulnerability allowed any user's file to be stolen
No preview is available. Read the original article for the full story.
Hacker News | Oct 10, 2026 | g-b-r
Automated excerpt
IntroductionSomeone adds you to a Telegram group. Together they turn a clicked link into arbitrary file read. So a path like this one:1 gives the attacker a deterministic path without ever needing the user name. From file read to account takeoverInterpretSendPath sends exactly one file per invocation: if an instruction file holds several file: lines, only the last one counts.
Selected automatically from source text; not independently written or fact-checked. Read the original for full context.