Telegram Desktop存在严重安全漏洞,未转义的IPC分隔符使任何用户可通过点击精心构造的链接读取任意磁盘文件并将其发送给攻击者1。该漏洞的威胁范围包括登录会话文件(如tdata/D877F783D5D3EF8C)和加密数据密钥文件(tdata/key_datas),攻击者可借此实现一次点击的账户完全接管1。
攻击链涉及两个核心缺陷:IPC通信中未转义的分隔符,以及interpret:URI方案缺少授权检查1。攻击者通过向受害人发送包含指令文件的组消息和伪装的HTTPS链接来实施攻击,而群组中最大8 MiB的文件会自动下载,进一步降低了用户的防范难度1。
官方已在7.2.9版本中修复此漏洞,修复日期为2026年9月16日1。修复措施包括转义百分比前缀的十六进制编码、移除interpret://方案以及添加连接级别的命令验证1。用户应升级至7.2.9及更高版本以获得安全保护1。
Telegram Desktop contained a critical security flaw that enabled attackers to steal any user's files through a single click, affecting all versions prior to 7.2.9 1. The vulnerability stemmed from unescaped IPC separators in the application's inter-process communication mechanism, which allowed malicious actors to read arbitrary disk files and transmit them to an attacker by crafting specially designed links 1.
The attack vector was particularly dangerous because it could lead to complete account takeover 1. Attackers could send a group message containing an instruction file paired with a disguised HTTPS link, and a single click from the victim would expose sensitive data, including login session files and encrypted data keys stored in the tdata/key_datas and tdata/D877F783D5D3EF8C directories 1. The exploit was made more feasible by the application's default behavior of automatically downloading files up to 8 megabytes from group chats 1.
The flaw involved two core security gaps: unescaped delimiters in IPC communications and a lack of authorization checks in the interpret: URI scheme 1. Telegram addressed the issue in version 7.2.9, released on September 16, 2026, by removing the interpret:// protocol handler, escaping hexadecimal-encoded prefixes in IPC communications, and implementing connection-level command validation 1.
评论
还没有评论,欢迎留下第一条。