A major security flaw was discovered in Telegram Desktop, allowing hackers to steal sensitive files from victims’ computers, including those from their cryptocurrency wallets. The vulnerability affected versions up to 7.2.8 and exploited links in the tg:// format to execute hidden commands without consent. Attackers could thus retrieve private keys and steal funds in bitcoins and other cryptos. The flaw was patched by Telegram in version 7.2.9, released on September 17, without prior public disclosure despite a report on June 25. No real-world exploitation has been confirmed so far, but users are advised to update the application and secure their private keys.
Source: Read the original article

