The vulnerability is embarrassingly mechanical. Telegram Desktop registers a custom URI scheme (tg://) so the OS routes links to it. When a second instance launches and finds the first already running, it serializes the URL into a semicolon-delimited text format and passes it over a local socket. The format uses semicolons as command separators. The URL is never escaped. A semicolon inside the URL becomes a command boundary on the receiving end. That is the entire injection primitive: craft a link containing a semicolon, and the running Telegram instance will interpret everything after it as a separate instruction. The injection alone would be limited — the IPC protocol only accepts four commands, and three are harmless. But the fourth, OPEN:, accepts any URL scheme without filtering. This reaches an internal, unregistered URI handler called interpret:, originally built so Telegram's own release scripts could automatically post builds to channels. The interpret: handler reads a file from disk, parses it for a destination channel and a file path, then sends that file to the specified chat. It performs zero authorization checks. It was never meant to be reachable from outside the local machine, but the IPC injection makes it reachable from a link in any group chat. The attack chain requires placing an instruction file on the victim's disk at a predictable path. Telegram Desktop's default configuration auto-downloads files under 8 MiB received in group chats to a standard folder. On Windows, that folder sits at a deterministic relative path from Telegram's working directory. The attacker sends the instruction file into the group, Telegram downloads it automatically, and the attacker knows exactly where it landed — no username needed, because relative path traversal (../../../Downloads/Telegram Desktop/) resolves from Telegram's own data directory. The instruction file tells interpret: which local file to read and which chat to send it to. The attacker points file: at whatever they want — SSH keys, browser credential stores, cloud tokens — and channel: at a chat they control. Multiple instruction files can be stacked into a single malicious link via repeated OPEN:interpret: injections separated by semicolons. One click exfiltrates multiple files. The severity rating of 8.1 High (CVSS 3.1) reflects the reality: no privileges required, no prior access needed, network-deliverable, one user interaction (a click), and the result is full confidentiality and integrity compromise. The session authorization files Telegram stores locally are the crown jewels — possessing them is account takeover. The fix landed in version 7.2.9, commit db3405699f, assigned CVE-2026-10718. What makes this chain instructive is that neither defect is exotic. Unescaped delimiters in serialization formats are a known bug class older than most working programmers. Internal-only functionality left reachable through unexpected entry points is a design pattern that fails predictably. The interpret: scheme was safe when it could only be invoked from the command line; the moment the IPC socket became a second entry point, the threat model changed and the authorization model did not. Two ordinary mistakes, neither catastrophic alone, combined into a one-click account takeover affecting every Telegram Desktop installation through 7.2.8.