Get the latest tech news

Telegram Desktop vulnerability allowed any user's file to be stolen


An unescaped separator in Telegram Desktop’s single-instance IPC lets one clicked link read arbitrary files off the disk and send them to the attacker, session files included.

None

Get the Android app

Or read this on Hacker News

Read more on:

Photo of user

user

Photo of file

file

Photo of Telegram Desktop

Telegram Desktop

Related news:

News photo

systemd-appd Out For Review To Centralize Tracking Of User's Apps

News photo

DoGBench: The first user-facing docs generation benchmark. No model scores >50%

News photo

Meta disputes claim that Muse read a user’s private messages without permission