← Back to context

Comment by g-b-r

20 hours ago

This link has already been posted with https://news.ycombinator.com/item?id=50019667 , but that post's title ("Telegram Desktop: one-click account takeover") doesn't say that the vulnerability allowed also any user-accessible file on the disk to be stolen.

This aspect is also not highlighted much in the article, which weirdly mostly focuses on the account takeover.

To me it seems something remarkable enough to warrant reposting the link with a different title.

Somewhat astonishingly, the core of the vulnerability comes from an internal url scheme added to Telegram to... help them publish their releases on their channel.

The Telegram developers saw no better way to do that than adding an internal tool which uploads any file it's told to.

Everyone else publishing their app on Telegram is able to do that with a script, but they had to do it that way.

It's true that it was exploitable only in a somewhat convoluted way, but still, it's an obviously dangerous feature.

Anyhow, yes, clicking on a link in Telegram Desktop was enough to have any user's file exfiltrated and to access or take over their account.

That is such a JiaTan grade feature because it’s an insane way to implement it but also plausibly deniable.