The post discusses a potential exploit in Telegram's web client that allows an attacker to gain access to a user's account using a URL with the account's token. The post also highlights the shared session between different web clients and the difficulty in exploiting the vulnerability remotely. The author suggests a mitigation similar to QR code logins.

16m read time From lyra.horse
Post cover image
1 Comment

Sort: