A vulnerability in Telegram Desktop allowed attackers to steal any user's files by injecting malicious commands through crafted links. When a user clicked a link in a group chat, an attacker could exploit improper URL serialization and an unfiltered internal URI scheme called interpret: to read arbitrary files without user confirmation.