Remix.run Logo
▲ Telegram Desktop vulnerability allowed any user's file to be stolen(beaksec.github.io)
188 points by g-b-r 8 hours ago | 93 comments
▲SpacePortKnight 3 hours ago | parent | next [-]

I think it is one of the reasons why I am always hesitant to install any software on my windows pc. Web versions are often more than good enough.

▲modeless 2 hours ago | parent | next [-]

Yes. I'm constantly annoyed by the dark patterns Zoom and Slack use to trick you into downloading their desktop apps. The web experience is practically indistinguishable and much more secure.

▲freehorse 2 hours ago | parent | next [-]

> The web experience is practically indistinguishable

The web experience is actually better, as eg there I can do web searches when right clicking sth with my default search engine without slack highjacking the options to force me onto google.

▲miroljub 2 hours ago | parent | prev [-]

Slack web app experience on mobile phones is abysmal.

▲gvfsa 2 hours ago | parent [-]

They are talking about desktop apps.

▲feeeeeany 28 minutes ago | parent [-]

Both are being talked about actually

▲Eueudhsbsj32 2 hours ago | parent | prev | next [-]

When I really need to run an app on my Linux laptop, it always gets its own bubblewrap container.

▲monster_truck 2 hours ago | parent | prev | next [-]

Don't let yourself be fooled into thinking this is enough. Plenty of examples of, especially through wasm, being able to reach far beyond what they're supposed to.

It gets buttoned up fast and is always getting better, but its absolutely not a silver bullet.

▲Fethbita 17 minutes ago | parent [-]

If you enable lockdown mode on your iPhone and Mac, WASM is disabled through Safari. If absolutely needed, an alternative browser like Firefox can be used for those sites.

▲ 2 hours ago | parent | prev | next [-]
[deleted]
▲Razengan 2 hours ago | parent | prev [-]

Even on Mac, where apps like Dropbox showed you a FAKE DIALOG to STEAL YOUR ADMIN PASSWORD:

https://news.ycombinator.com/item?id=12463338

▲yard2010 31 minutes ago | parent | next [-]

Something about reading this blog post knowing every letter and screenshot done manually with no LLM gave me the chills

▲Kwpolska 37 minutes ago | parent | prev [-]

Is this a fake dialog, or just the standard system sudo dialog, which used to allow app developers to show an arbitrary reason string?

▲RachelF an hour ago | parent | prev | next [-]

It looks very bad that Telegram took almost 3 months to fix this vulnerability.

Reported 25 June

Fixed 16 September

I wonder why it took them so long?

▲ 31 minutes ago | parent | next [-]
[deleted]
▲k__ an hour ago | parent | prev [-]

They are restructuring their companies regularly and keep the core company small.

▲usr1106 4 hours ago | parent | prev | next [-]

I don't use Telegram Desktop or Windows. But that's exactly the reason why I run Firefox in a firejail sandbox on Linux. The browser has only access to my Downloads folder. I know that it's considered untrusted and don't keep any files there for a long time.

▲freebsd_lovefes 4 hours ago | parent | next [-]

Or the reason to run Firefox in a FreeBSD jail to get server-grade security. But the question is can an attacker get access to the Firefox profile data? Because you cannot block that from Firefox, obviously.

▲usr1106 4 hours ago | parent [-]

Sure, to some degree you must trust your browser. In the extreme case you could open a new, non-persistent browser session for every page you visit. Could be slightly inconvenient...

▲bmacho an hour ago | parent [-]

Or you could have 2 (or 3) separate browser sessions, one for only important stuff, and one for fun.

▲barrkel 4 hours ago | parent | prev | next [-]

I guess it also has access to the cookies for all your logins.

▲usr1106 4 hours ago | parent [-]

Yes, it has access to the internal storage mechanisms of the browser.

I used to use Cookie Auto Delete for years. But when I last checked it seemed unmaintained. I log out of all somewhat important services anyway every time I am done.

For important stuff like banking I use Firefox containers.

Yeah, all of them could have their weaknesses and vulnerabilities. I just hope no attacker hits exactly the stack I use...

▲eddythompson80 3 hours ago | parent [-]

Personally I only open Firefox on Linux booted from a read only usb. In theory there could be a firmware vulnerability in the CPU that could let it write persistent data to the UEFI firmware, but I hope the possibility is small.

▲ShinyLeftPad 31 minutes ago | parent [-]

What makes it doubly funny is that the OP is not even about any browser vulnerability, it's a hole in desktop client IPC

▲iririririr 4 hours ago | parent | prev | next [-]

interesting you mention. because Firefox doesn't have a way to disable the single instance functionality which was used on this telegram vulnerability.

one long time Firefox contributor have been for a couple years now removing every part of the --noremote option. even botching (Ooops!) the console notice that the flag was no-op some time ago.

▲lxgr 2 hours ago | parent | next [-]

Which Firefox functionality was used in the Telegram vulnerability? Isn’t this all about the desktop app?

▲g-b-r an hour ago | parent [-]

None, I'm not sure what the other user was talking about

Telegram wanting to be single instance means that it has to use some serialization, and it not escaping semicolons enables a part of the attack.

▲lxgr an hour ago | parent [-]

What does "being single instance" mean here?

▲g-b-r 37 minutes ago | parent [-]

That only one instance of Telegram can run at any time.

And if you open a Telegram link it will open in the existing instance.

Windows uri handlers actually always create a new process, though; so if you want this single instance behavior, you have to do some check at the start of the process and communicate the uri to the previously running process (as explained in the article).

▲yjftsjthsd-h 4 hours ago | parent | prev [-]

> removing every part of the --noremote option

What's this now? I'm using that to handle multiple profiles and haven't noticed anything breaking

▲maqp 4 hours ago | parent | prev [-]

The little I have to run Telegram Desktop for, I run in a VM. I'd never let the little oligarch's code touch my desktop OS.

▲lifeisloving 3 hours ago | parent [-]

I dont write off software because where the person that made it was born. I personally think thats the same thing as refusing to eat at a black owned resturaunt because of the owners skin color.

Seems like many people do this when it comes to russian tech. Im American and I certainly trust my data in the hands of a foriegn government/entity (which is not even the case for telegram), than my own. Even if it was a russian op (its not the Ukrainian military literally used telegram for years), the russian government cant touch me.

▲ornornor 3 hours ago | parent | next [-]

Telegram is a double threat: the company is Russian and the founder was arrested then mysteriously released without any charges in France. Given why France wanted him and arrested him, the fact they released him a few days later with no charge annihilated the little shred of trust I had in this Russian piece of software, personally.

▲g-b-r 3 hours ago | parent | prev [-]

You're sure you're replying to the right message? It doesn't mention any country or nationality...

Anyhow, people don't write off Telegram because it's Russian, but for many legitimate reasons.

There are indications that it could be much closer to the Russian government than they pretend, but that matters not because Russians are bad people, but because the current government of Russia is an aggressive dictatorship.

The Ukrainian military literally used Telegram for years and now literally banned it.

Maybe in part for this Ukrainian article: https://texty.org.ua/articles/112347/eight-signsof-danger-te...

▲feelamee 2 hours ago | parent | next [-]

> Anyhow, people don't write off Telegram because it's Russian, but for many legitimate reasons.

> There are indications that it could be much closer to the Russian government than they pretend

Can you give more details, please? I'm using telegram a lot and want to know if there is something...

▲g-b-r an hour ago | parent [-]

https://texty.org.ua/articles/112347/eight-signsof-danger-te... , https://medium.com/@anton.rozenberg/pavel-durov-sued-senior-...

▲lxgr 2 hours ago | parent | prev | next [-]

The main reason I consider it suspicious is that they are so adamant about not needing end-to-end encryption.

Even assuming they are fully legitimate today, if this ever changes and somebody gets access to their infrastructure, they immediately get a treasure trove of historical messages.

▲lifeisloving 33 minutes ago | parent | prev [-]

Calling him an oligarch, it was implied

▲ShinyLeftPad 23 minutes ago | parent [-]

There are oligarchs in other countries like USA (Musk)

▲Panzerschrek 5 hours ago | parent | prev | next [-]

It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file. Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory (like downloads for a browser or Telegram-client).

▲yjftsjthsd-h 4 hours ago | parent | next [-]

> It's not strictly-speaking a Telegram-specific vulnerability. It's a vulnerability of all modern desktop operating systems allowing any user process to read/write any user file.

No, it's definitely a Telegram specific vulnerability. It might be worse because of poor defense in depth, but without Telegram itself being vulnerable it wouldn't matter.

▲simonra 4 hours ago | parent | prev | next [-]

At the same time the mobile operating systems are vulnerable to vendor lock-in due to the absence of this functionality. It is clearly a worse problem that a user can't give their backup system access to the photos stored by other applications (often social media), or for instance reliably capture media streams to use in for instance a remixing application. Bringing custom clients when the software originally used to create the interesting files starts acting against the users by introducing subscriptions or being abandoned is another example of the user dictating what software accesses what files is critical to secure the users operations. Consumers need security against commercial interests infinitely much more than commercial interests need protections against consumers, and it would be unethical to enable commerce at the expense of individuals like the mobile operating systems do.

▲lxgr 2 hours ago | parent [-]

There is a lot of middle ground between “every app can do anything as the user” and “no shared file system, no user access to app ‘owned’ files”.

▲ShinyLeftPad 22 minutes ago | parent | prev | next [-]

> vulnerability of all modern desktop operating systems allowing any user process to read/write any user file

not true on macos.

▲BoppreH 10 minutes ago | parent [-]

Or Linux with Flatpaks.

▲nvme0n1p1 5 hours ago | parent | prev | next [-]

If you don't believe it's a vulnerability, then you must believe that tricking Telegram into uploading your messages database to the attacker, leaking all your private conversations, is A-OK? Telegram owns that file, after all.

▲Panzerschrek 5 hours ago | parent [-]

I didn't say it's not a vulnerability. It is clearly one. But allowing such vulnerabilities to deal damage beyond data of its host application is an OS vulnerability.

▲lxgr 2 hours ago | parent | prev | next [-]

Yes, and there are many ways for apps to opt into this, to limit their own blast radius in a case like this.

Does Telegram do that, or do they consider themselves beyond bugs, just like they consider themselves too clever and untouchable by anyone to need end-to-end encryption?

▲eviks 5 hours ago | parent | prev | next [-]

That's broadly-speaking a vulnerable design of all OSes, but strictly speaking it is a bug in Telegram that is now fixed at the app level. Though sandboxes / app isolation solutions exist even in the broadly vulnerable OSes, so apps could use them already today to avoid such issues in the future?

▲nottorp 4 hours ago | parent | prev | next [-]

> Ideally all programs should be isolated from the underlying filesystem and be able to read only their own files and files from per-program data directory

So how will you spam all the group chats you're on with meme gifs downloaded from facebook then? :)

▲Panzerschrek 3 hours ago | parent [-]

Download an image from Facebook into browser's private downloads directory, copy it using a file-manager application (one of the exceptional applications having full filesystem access) into Telegram's private directory, upload it into chats you need to post it.

The file-manger application managed above is a single point of failure, of course. So, it should be allowed to use only one provided by OS vendor.

▲lukan 32 minutes ago | parent [-]

Sounds like effort, people don't like effort when spreading memes, so would be enraged if this would be the default now, or nobody would activate it.

There is a lot of middle ground, like having a shared folder for access. "Downloads" might be a good default, if clearly communicated, that anything in there, is accessible by any app.

▲saagarjha 5 hours ago | parent | prev | next [-]

Telegram is available sandboxed from the Mac App Store on macOS.

▲lxgr 2 hours ago | parent | next [-]

It could easily sandbox itself in the non-store distribution as well, yet the developers apparently choose not to.

▲gvfsa 2 hours ago | parent | prev | next [-]

That is not the same app.

▲saagarjha 2 hours ago | parent [-]

I know, it's (slightly) better

▲zorked 4 hours ago | parent | prev | next [-]

It is also sandboxed in Flatpak.

▲ 2 hours ago | parent | prev [-]
[deleted]
▲g-b-r 5 hours ago | parent | prev | next [-]

It is.

Not all user processes upload those files somewhere surreptitiously.

Of course operating systems should support that isolation (hopefully in some better way than the hell that smartphones are), but it's not like Telegram can blame the OS for this vulnerability.

▲Panzerschrek 5 hours ago | parent [-]

> Not all user processes upload those files somewhere surreptitiously.

Only if you have access to full source code, can audit it (including each update) and somehow can prove that it has no vulnerabilities. Otherwise one should assume that any application is potentially-harmful and/or vulnerable.

▲yjftsjthsd-h 3 hours ago | parent | next [-]

No, that kind of audit is neither necessary nor sufficient. (A firewall works without application source code, and trusting trust means we can hand wave anything even with source.)

▲g-b-r 5 hours ago | parent | prev [-]

Ok, at least if it has network access, but can you recognize that this was a vulnerability, and that you're talking of something only tangential to it?

▲penskymaterial 5 hours ago | parent | prev [-]

> It's a vulnerability of all modern desktop operating systems

Uhm, OpenBSD would like a word, buddy.

https://man.openbsd.org/unveil

▲erelong 6 hours ago | parent | prev | next [-]

I thought telegram was flagged as insecure like a decade ago, it's never really been "very secure"

Like any number of articles like this: https://hackernoon.com/7-reason-why-telegram-is-insecure-by-...

▲lxgr 2 hours ago | parent | next [-]

It was, but most people will believe what their peers (real or parasocial) say over the collective screams of every security researcher on the planet, so here we are.

▲misiek08 4 hours ago | parent | prev | next [-]

Still we are using it, because UX kills any other app and people that are (probably) behind it will cause almost no harm to casual, not-interesting people :)

And yes, I know that by default chats are not E2E, that phone number has way too many effects on accounts etc. Still, UX and agencies interested in important people are more welcome than data selling, ad-based companies.

▲lxgr 2 hours ago | parent | next [-]

What a bizarre threat model. Why would you rather have your data with who knows who than just your metadata?

And what UX problems exactly is Telegram solving that its many competitors aren’t? I hear this all the time, but I use both Telegram and WhatsApp and I haven’t found anything lacking in the latter, UX wise.

▲maxgashkov an hour ago | parent [-]

> and I haven’t found anything lacking in the latter, UX wise

I'm sorry if I'll sound condescending, but you probably don't use either frequently enough. With telegram it's the little (and sometimes not so little) things, e.g.:

  - voice message transcription
  - you can select part of the message via long-press and use it as a quote when responding
  - massively more complex formatting possible
  - bots as the first class citizens not gated behind some bullshit 'Business' KYC/subscription
  - is not crippled by prohibiting system-level phonebook access like whatsapp
  - extreme flexibility in managing large groups, mostly due to the bot point above
  - and many more
All of the above does not excuse lack of e2e by default, this is almost embarrassing in 2026 now, but Telegram is the most polished IM experience of all the apps I have tried.
▲lxgr 25 minutes ago | parent [-]

I use them daily, so we might just have different priorities.

Bot access is definitely better in Telegram; that’s what I sometimes use it for.

WhatsApp has voice message transcription now, but fortunately I don’t receive many. (I consider it pretty rude to put the effort of messaging on the recipient because the sender can’t be bothered to type or transcribe on their side.)

Everything else you mentioned is a minor inconvenience to me. Knowing the provider can’t mine my message data more than makes up for that.

▲maqp 4 hours ago | parent | prev [-]

"will cause almost no harm to casual, not-interesting people"

Yeah same can be said for Facebook and WhatsApp that Durov vehemently claims should not be trusted with user's data. Maybe it's a ploy for the Mark Zuckerberg of Russia to get the data of people.

Also, Telegram doesn't have to sell it's users if it's an FSB honeypot.

▲mschuster91 an hour ago | parent [-]

Well, it makes sense from a threat modeling perspective. If you're Russian, you should use Whatsapp because it is unlikely Whatsapp will cooperate with the Russian dictatorship, but in Western countries, you can assume that anything from Meta, Google or Apple that's in any way useful (and even if it's just metadata) can and will end up in the data lakes at the NSA.

▲g-b-r 6 hours ago | parent | prev | next [-]

Absolutely, but mostly for their protocols, statements, people and infrastructure.

A file exfiltration vulnerability is still noteworthy.

▲phoronixrly 5 hours ago | parent | prev | next [-]

Here's one from Filippo

The Most Backdoor-Looking Bug I’ve Ever Seen - https://words.filippo.io/telegram-ecdh/

▲TZubiri 4 hours ago | parent | prev [-]

It has this feature where it tells you about other users that are on the platform. I mean it's not a huge leak, but right off the bat it's pretty poor security posture. For an app that competes with other chat apps on supposedly being more secure and privacy aware, it does worse than whatsapp on that end.

▲lukan 28 minutes ago | parent [-]

"For an app that competes with other chat apps on supposedly being more secure and privacy aware"

It mainly competes against facebook and other social media plattforms. The privacy is clearly wrong and only believed by non technical people (which can be amusing, when on TG someone posts a link to FB, or a WhatsApp group and people chime in and lecturing others that they should not use that as it is insecure and owned by a big company who will sell them out).

▲g-b-r 8 hours ago | parent | prev | next [-]

This link has already been posted with https://news.ycombinator.com/item?id=50019667 , but that post's title ("Telegram Desktop: one-click account takeover") doesn't say that the vulnerability allowed also any user-accessible file on the disk to be stolen.

This aspect is also not highlighted much in the article, which weirdly mostly focuses on the account takeover.

To me it seems something remarkable enough to warrant reposting the link with a different title.

Somewhat astonishingly, the core of the vulnerability comes from an internal url scheme added to Telegram to... help them publish their releases on their channel.

The Telegram developers saw no better way to do that than adding an internal tool which uploads any file it's told to.

Everyone else publishing their app on Telegram is able to do that with a script, but they had to do it that way.

It's true that it was exploitable only in a somewhat convoluted way, but still, it's an obviously dangerous feature.

Anyhow, yes, clicking on a link in Telegram Desktop was enough to have any user's file exfiltrated and to access or take over their account.

▲arjie 5 hours ago | parent [-]

That is such a JiaTan grade feature because it’s an insane way to implement it but also plausibly deniable.

▲opengrass 5 hours ago | parent | prev | next [-]

doas jexec -U opengrass tellyjail env DISPLAY=:0 Telegram

▲g-b-r 5 hours ago | parent [-]

Yeah, something like that would not have prevented the account takeover part, though, which relies on Telegram's own files; or the access to cached files.

▲ 6 hours ago | parent | prev | next [-]
[deleted]
▲KingOfCoders 6 hours ago | parent | prev | next [-]

It's not a bug it's a feature.

▲iririririr 4 hours ago | parent [-]

was a feature.

technically, this is one agency burning the feature of another agency.

▲maqp 4 hours ago | parent [-]

The main spy feature that is Telegram collecting 100% of content and metadata is the main feature for every intelligence agency who bothers to ask Mythos to find zero days to pwn the servers.

▲anon_cow1111 5 hours ago | parent | prev | next [-]

Imagine if you forgot to update your phone number with your personal bank, and then some random guy was given full access to your account and all of its contents. And even if you dug through the account options and set a 2FA password (normally disabled) he could still just delete your account outright.

Last I checked, that's exactly how Telegram works by default. It's laughable to consider a service tied to a phone number secure.

▲sunaookami an hour ago | parent | next [-]

You would still get a notification inside Telegram that someone else logged in (plus it sends the login code to your session first before you can fallback to SMS) and you can log them out. The "attacker" can't delete your account or log out your sessions because he can't use certain features on a fresh login, there is a downtime. But yeah, he can read all your chats. Same should be true for any app that uses phone number login. That's why there is a password feature.

▲msh 3 hours ago | parent | prev [-]

I guess that’s the idea with phone number based services. Imagine if you could not sign up for telegram/ WhatsApp/ whatever because someone used your number before you.

▲colordrops 4 hours ago | parent | prev | next [-]

well duh

▲GreenLightGo 2 hours ago | parent | prev | next [-]

[dead]

▲hulitu 28 minutes ago | parent | prev | next [-]

> Telegram Desktop vulnerability allowed any user's file to be stolen

Wait till they find out about web browsers. /s

▲bashtoni 4 hours ago | parent | prev | next [-]

Russian social media app has backdoor. Who would have thought?

(Yes, I know they're technically Dubai based now)

▲maqp 4 hours ago | parent [-]

Yet the oligarch who supposedly lives in exile has visited Russia over 60 times since https://kyivindependent.com/kremlingram-investigation-durov/

▲seeknotfind 4 hours ago | parent | prev [-]

Wow, that's pretty bad, but imagine if 50% of software allowed this to happen at any time, and it was discovered on December 1st, 2026. What would happen?

▲petterroea 4 hours ago | parent [-]

is that a threat or an ai doomsday whataboutism