“Any sufficiently complex input format is indistinguishable from
bytecode; the code receiving it is indistinguishable from a vir-
tual machine.”
show comments
bita_nidir
Related: could we please stop, by default, allowing software to:
a) access all your files, and
b) roam the internet at will.
That was somewhat OK in the 80s, but it hasn't been since.
show comments
crossroadsguy
One of the challenges with Telegram is - they regularly re-enable settings inside the app/account that you had specifically disabled. So at any point you don't know what is happening and what is not. Meaning, even if you didn't see a thing, a malicious file might be sitting all warm and fuzzy on your computer - among possible other things. I used to like the snappiness of this app (and it is still snappier than almost all other IM apps combined, by a margin), but after a while I realised it was a ticking time-bomb (to keep it installed on the desktop) and possibly a scammer safe haven, nothing else.
show comments
SpacePortKnight
I think it is one of the reasons why I am always hesitant to install any software on my windows pc. Web versions are often more than good enough.
show comments
usr1106
I don't use Telegram Desktop or Windows. But that's exactly the reason why I run Firefox in a firejail sandbox on Linux. The browser has only access to my Downloads folder. I know that it's considered untrusted and don't keep any files there for a long time.
show comments
Kinrany
When criticizing Telegram, I wish people focused on the actual smoking guns and didn't include random fluff one has to cut through.
As a Telegram user, my current impression of the platform is that they are a tiny elite team, they focus very heavily on creating a polished product, and are somewhat arrogant about all of that.
The most common criticism that I see and understand is the lack of E2EE by default. But I'm not aware of a messenger that provides a good UX for that. For most people, losing access to the account is a much greater risk. (The trade-off has changed somewhat now that everyone is getting hacked by AI and thus Telegram's whole dataset leaking becomes a concern.)
The criticism that I agree the most with is phone numbers being used for authentication. Even if Telegram still wants to know everyone's phone numbers for growth reasons, as far as I'm aware for authn phone numbers are strictly worse than emails.
On the positive side, they still have a proper API, open source their clients and allow third-party clients. All of which seem non-optional for any messenger that claims to prioritize security.
show comments
Narushia
It's great that this writeup was published, but unfortunately the text is full of claudisms and made me close the tab pretty quickly.
show comments
Panzerschrek
It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file. Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory (like downloads for a browser or Telegram-client).
show comments
robertlane0
Telegram and security don't really belong in the same sentence anyways. Say what you will about Signal but they at least have better cryptography and more transparency about what software they're running.
RachelF
It looks very bad that Telegram took almost 3 months to fix this vulnerability.
Reported 25 June
Fixed 16 September
I wonder why it took them so long?
show comments
erelong
I thought telegram was flagged as insecure like a decade ago, it's never really been "very secure"
I wonder how much of Apple's announcement around disallowing full system disk access was from this as opposed to Muse, et al.
wrcoro
Does its official desktop client support "Secret Chats" (E2EE) yet? Last time I used Telegram before moving to more reliable IM platforms that feature was officially unsupported on desktop and there was even some community effort¹ to make a pull request with paid contributions totally ignored by Pavel Durov and his team
Telegram is worse than WhatsApp. No E2EE by default in 2026 is insane and Telegram's marketing is so deceptive.
g-b-r
This link has already been posted with https://news.ycombinator.com/item?id=50019667 , but that post's title ("Telegram Desktop: one-click account takeover") doesn't say that the vulnerability allowed also any user-accessible file on the disk to be stolen.
This aspect is also not highlighted much in the article, which weirdly mostly focuses on the account takeover.
To me it seems something remarkable enough to warrant reposting the link with a different title.
Somewhat astonishingly, the core of the vulnerability comes from an internal url scheme added to Telegram to... help them publish their releases on their channel.
The Telegram developers saw no better way to do that than adding an internal tool which uploads any file it's told to.
Everyone else publishing their app on Telegram is able to do that with a script, but they had to do it that way.
It's true that it was exploitable only in a somewhat convoluted way, but still, it's an obviously dangerous feature.
Anyhow, yes, clicking on a link in Telegram Desktop was enough to have any user's file exfiltrated and to access or take over their account.
show comments
skeledrew
This is really good to know. Telegram is my primary means of communication, and a bunch of other things, and even though I'm not exactly exposed (I have password set, and only a few people can yank me into a group), I'm running a bit of a custom-method install that I don't update much.
sehw
I use Signal btw.
opengrass
doas jexec -U opengrass tellyjail env DISPLAY=:0 Telegram
show comments
anon_cow1111
Imagine if you forgot to update your phone number with your personal bank, and then some random guy was given full access to your account and all of its contents.
And even if you dug through the account options and set a 2FA password (normally disabled) he could still just delete your account outright.
Last I checked, that's exactly how Telegram works by default. It's laughable to consider a service tied to a phone number secure.
show comments
syngrog66
if the user values security and privacy would not be using Telegram
KingOfCoders
It's not a bug it's a feature.
show comments
buckle8017
I am shocked......
ramesh31
I mean it's pretty obvious these things (Signal, et. al) are just honeypots for the three letter agencies, right?
show comments
colordrops
well duh
hulitu
> Telegram Desktop vulnerability allowed any user's file to be stolen
Wait till they find out about web browsers. /s
bashtoni
Russian social media app has backdoor. Who would have thought?
(Yes, I know they're technically Dubai based now)
show comments
seeknotfind
Wow, that's pretty bad, but imagine if 50% of software allowed this to happen at any time, and it was discovered on December 1st, 2026. What would happen?
I once read The Bugs We Have to Kill: https://www.usenix.org/publications/login/aug15/bratus and one particular thing that has stuck with me forever:
“Any sufficiently complex input format is indistinguishable from bytecode; the code receiving it is indistinguishable from a vir- tual machine.”
Related: could we please stop, by default, allowing software to:
That was somewhat OK in the 80s, but it hasn't been since.One of the challenges with Telegram is - they regularly re-enable settings inside the app/account that you had specifically disabled. So at any point you don't know what is happening and what is not. Meaning, even if you didn't see a thing, a malicious file might be sitting all warm and fuzzy on your computer - among possible other things. I used to like the snappiness of this app (and it is still snappier than almost all other IM apps combined, by a margin), but after a while I realised it was a ticking time-bomb (to keep it installed on the desktop) and possibly a scammer safe haven, nothing else.
I think it is one of the reasons why I am always hesitant to install any software on my windows pc. Web versions are often more than good enough.
I don't use Telegram Desktop or Windows. But that's exactly the reason why I run Firefox in a firejail sandbox on Linux. The browser has only access to my Downloads folder. I know that it's considered untrusted and don't keep any files there for a long time.
When criticizing Telegram, I wish people focused on the actual smoking guns and didn't include random fluff one has to cut through.
As a Telegram user, my current impression of the platform is that they are a tiny elite team, they focus very heavily on creating a polished product, and are somewhat arrogant about all of that.
The most common criticism that I see and understand is the lack of E2EE by default. But I'm not aware of a messenger that provides a good UX for that. For most people, losing access to the account is a much greater risk. (The trade-off has changed somewhat now that everyone is getting hacked by AI and thus Telegram's whole dataset leaking becomes a concern.)
The criticism that I agree the most with is phone numbers being used for authentication. Even if Telegram still wants to know everyone's phone numbers for growth reasons, as far as I'm aware for authn phone numbers are strictly worse than emails.
On the positive side, they still have a proper API, open source their clients and allow third-party clients. All of which seem non-optional for any messenger that claims to prioritize security.
It's great that this writeup was published, but unfortunately the text is full of claudisms and made me close the tab pretty quickly.
It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file. Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory (like downloads for a browser or Telegram-client).
Telegram and security don't really belong in the same sentence anyways. Say what you will about Signal but they at least have better cryptography and more transparency about what software they're running.
It looks very bad that Telegram took almost 3 months to fix this vulnerability.
Reported 25 June
Fixed 16 September
I wonder why it took them so long?
I thought telegram was flagged as insecure like a decade ago, it's never really been "very secure"
Like any number of articles like this: https://hackernoon.com/7-reason-why-telegram-is-insecure-by-...
I wonder how much of Apple's announcement around disallowing full system disk access was from this as opposed to Muse, et al.
Does its official desktop client support "Secret Chats" (E2EE) yet? Last time I used Telegram before moving to more reliable IM platforms that feature was officially unsupported on desktop and there was even some community effort¹ to make a pull request with paid contributions totally ignored by Pavel Durov and his team
[1] https://github.com/marcovelon/tdesktop/blob/NoSecretChats/RE...
Telegram is worse than WhatsApp. No E2EE by default in 2026 is insane and Telegram's marketing is so deceptive.
This link has already been posted with https://news.ycombinator.com/item?id=50019667 , but that post's title ("Telegram Desktop: one-click account takeover") doesn't say that the vulnerability allowed also any user-accessible file on the disk to be stolen.
This aspect is also not highlighted much in the article, which weirdly mostly focuses on the account takeover.
To me it seems something remarkable enough to warrant reposting the link with a different title.
Somewhat astonishingly, the core of the vulnerability comes from an internal url scheme added to Telegram to... help them publish their releases on their channel.
The Telegram developers saw no better way to do that than adding an internal tool which uploads any file it's told to.
Everyone else publishing their app on Telegram is able to do that with a script, but they had to do it that way.
It's true that it was exploitable only in a somewhat convoluted way, but still, it's an obviously dangerous feature.
Anyhow, yes, clicking on a link in Telegram Desktop was enough to have any user's file exfiltrated and to access or take over their account.
This is really good to know. Telegram is my primary means of communication, and a bunch of other things, and even though I'm not exactly exposed (I have password set, and only a few people can yank me into a group), I'm running a bit of a custom-method install that I don't update much.
I use Signal btw.
doas jexec -U opengrass tellyjail env DISPLAY=:0 Telegram
Imagine if you forgot to update your phone number with your personal bank, and then some random guy was given full access to your account and all of its contents. And even if you dug through the account options and set a 2FA password (normally disabled) he could still just delete your account outright.
Last I checked, that's exactly how Telegram works by default. It's laughable to consider a service tied to a phone number secure.
if the user values security and privacy would not be using Telegram
It's not a bug it's a feature.
I am shocked......
I mean it's pretty obvious these things (Signal, et. al) are just honeypots for the three letter agencies, right?
well duh
> Telegram Desktop vulnerability allowed any user's file to be stolen
Wait till they find out about web browsers. /s
Russian social media app has backdoor. Who would have thought?
(Yes, I know they're technically Dubai based now)
Wow, that's pretty bad, but imagine if 50% of software allowed this to happen at any time, and it was discovered on December 1st, 2026. What would happen?