<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>vulnerabilities | OKHK 👀</title><description>(⁠◔⁠‿⁠◔⁠) Are you OK？✨ Thinking...</description><link>https://tg.okhk.net</link><item><title>Telegram Desktop 存在严重安全漏洞：一次点击即可窃取任意文件</title><link>https://tg.okhk.net/posts/11614</link><guid isPermaLink="true">https://tg.okhk.net/posts/11614</guid><pubDate>Fri, 09 Oct 2026 10:09:24 GMT</pubDate><content:encoded>&lt;div class=&quot;tgme_widget_message_forwarded_from accent_color&quot;&gt;Forwarded from &lt;a class=&quot;tgme_widget_message_forwarded_from_name&quot; href=&quot;https://t.me/tginfocn/1004&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;&lt;span&gt;Telegram Info 中文&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;image-list-container image-list-odd&quot;&gt;
      &lt;button type=&quot;button&quot; class=&quot;image-preview-button image-preview-wrap&quot; popovertarget=&quot;modal-11614-0&quot; popovertargetaction=&quot;show&quot; aria-label=&quot;Open image preview: Telegram Desktop 存在严重安全漏洞：一次点击即可窃取任意文件&quot;&gt;
        &lt;img src=&quot;/static/https://cdn5.telesco.pe/file/cUZDSNzDhgkH20BJwQYQHnp99f5mC5_qHLfQ8UfPGFoO3XZ8z-MRoUmIGWQrWS2wRKjerd1enDGxjB_qk9b-SHrx3a7Jnr8Nc-PyCVL9CvWDDIYtnF48VXmMGJvUgP0OWcoqF_7QSGfwpGRGx-jlCXde2mYjvFk5gbsP3aGA2NqyJXVYvenJnvNdUM6WdCCPhqVupo6H_R7EqYfMhPCJMX8z9J9Ncfny-BgLC1-uJCa7xjFAIh-9drNrdExXaYPEK9LeJUnWhP2lEPQGgGwwzvA9HtEy3kqEgNjKateSNUA4gQSzE63pHI4HObTDLRpJzuzov5qX07F8EpiDhw0a6Q.jpg&quot; alt=&quot;Telegram Desktop 存在严重安全漏洞：一次点击即可窃取任意文件&quot; width=&quot;800&quot; height=&quot;501&quot; loading=&quot;eager&quot; /&gt;
      &lt;/button&gt;
      &lt;div class=&quot;modal&quot; id=&quot;modal-11614-0&quot; popover=&quot;auto&quot; aria-label=&quot;Image preview&quot;&gt;
        &lt;button type=&quot;button&quot; class=&quot;modal__backdrop&quot; popovertarget=&quot;modal-11614-0&quot; popovertargetaction=&quot;hide&quot; aria-label=&quot;Close image preview&quot;&gt;&lt;/button&gt;
        &lt;button type=&quot;button&quot; class=&quot;modal__close&quot; popovertarget=&quot;modal-11614-0&quot; popovertargetaction=&quot;hide&quot; aria-label=&quot;Close image preview&quot;&gt;×&lt;/button&gt;
        &lt;div class=&quot;modal__surface&quot;&gt;
          
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;&lt;b&gt;&lt;span class=&quot;post-title-source&quot;&gt;Telegram Desktop 存在严重安全漏洞：一次点击即可窃取任意文件&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;如何保护自己：&lt;/b&gt;&lt;br /&gt; • &lt;b&gt;不要继续使用低于 7.2.9 的版本&lt;/b&gt;——请立即更新客户端。如果你使用的是非官方客户端，在相关更新发布之前，请暂时切换到官方客户端。&lt;br /&gt;&lt;br /&gt;&lt;b&gt;下载：&lt;/b&gt;  &lt;br /&gt; • Windows/macOS/Linux：&lt;a href=&quot;https://desktop.telegram.org/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;官方网站&quot;&gt;官方网站&lt;/a&gt;或 &lt;a href=&quot;https://github.com/telegramdesktop/tdesktop/releases&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;GitHub&quot;&gt;GitHub&lt;/a&gt;  &lt;br /&gt; • Windows：&lt;a href=&quot;https://apps.microsoft.com/detail/9nztwsqntd0s&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;Microsoft Store&quot;&gt;Microsoft Store&lt;/a&gt;  &lt;br /&gt; • macOS：&lt;a href=&quot;https://apps.apple.com/us/app/telegram/id747648890&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;App Store&quot;&gt;App Store&lt;/a&gt;  &lt;br /&gt; • Linux：&lt;a href=&quot;https://telegram.org/dl/desktop/flatpak&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;Flathub&quot;&gt;Flathub&lt;/a&gt;、&lt;a href=&quot;https://telegram.org/dl/desktop/snap&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;Snapcraft&quot;&gt;Snapcraft&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;给旧版客户端用户的建议：&lt;/b&gt;&lt;br /&gt;&lt;br /&gt; • &lt;b&gt;链接可能存在危险：点击任何链接时，都要仔细阅读弹出的窗口&lt;/b&gt;。如果 Telegram 显示的链接结构异常（例如以 &lt;code&gt;tg://&lt;/code&gt; 开头），请不要继续访问。&lt;br /&gt;&lt;br /&gt; • &lt;b&gt;不要在未设置本地锁定码的情况下使用客户端：&lt;/b&gt;启用锁定码功能后，&lt;code&gt;tdata&lt;/code&gt; 目录中的会话文件将被加密。即使这些文件泄露，也能防止攻击者立即接管账号。&lt;br /&gt;&lt;br /&gt;&lt;b&gt;问题的本质是什么？&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;一项漏洞 (&lt;a href=&quot;https://opennet.me/66431/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; title=&quot;CVE-2026-107181&quot;&gt;CVE-2026-107181&lt;/a&gt;) 在低于 7.2.9 版本的 Telegram Desktop 客户端中被发现。由于未对分隔符 &lt;code&gt;;&lt;/code&gt; 进行转义，&lt;code&gt;tg://&lt;/code&gt; 协议链接中的参数会被识别为独立的 IPC 命令。攻击者可以利用专用处理程序 &lt;code&gt;interpret:&lt;/code&gt;，让用户点击经过特制的链接后，在用户不知情且未获得用户确认的情况下，将系统中的文件发送到攻击者自己的频道。&lt;br /&gt;&lt;br /&gt;&lt;b&gt;主要风险&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;风险并不局限于窃取 &lt;code&gt;tdata&lt;/code&gt; 会话文件和劫持账号。利用该漏洞，攻击者可以静默窃取&lt;b&gt;计算机上用户有权访问的任意文件&lt;/b&gt;，包括文档、浏览器保存的会话、SSH 密钥、系统配置文件或加密货币钱包。&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;/search/result?q=%23security&quot; title=&quot;#security&quot;&gt;#security&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23desktop&quot; title=&quot;#desktop&quot;&gt;#desktop&lt;/a&gt; &lt;a href=&quot;/search/result?q=%23vulnerabilities&quot; title=&quot;#vulnerabilities&quot;&gt;#vulnerabilities&lt;/a&gt;</content:encoded></item></channel></rss>