Hacker News19h ago362 points197 commentslive

Telegram Desktop vulnerability allowed any user's file to be stolen

Telegram Desktop's local socket serialization flaw allows attackers to inject commands via semicolons in links, enabling arbitrary local file read via the internal 'interpret:' URI scheme, affecting versions through 7.2.8 (CVE-2026-107181).

Read the full story atbeaksec.github.io

Why this is in the Signal

LAXIMA AI Signal curates the highest-velocity stories across Hacker News, GitHub trending, and new Hugging Face / Replicate model releases — quality-filtered, deduplicated, and refreshed every four hours. This item surfaced from Hacker News with 362 points (by g-b-r). We link straight to the original source above — see the full live feed.

More AI Signal briefs

Get the Signal