Telegram RCE
twitter.com
twitter.com
Having that said, I think this should still be rejected by the server so it's weird that it worked that way. However, the issue is not as bad as the video claims it to be, a user will be warned.
"We can't confirm that such a vulnerability exists. This video is likely a hoax."
Disabling of automatic media parsing as suggested is absolutely a wise choice.
This would be pretty bad indeed if it were wormable.
where you could open an app by running window.open("C:\Windows\system32\cmd.exe")
This is a guess based on the behavior in the video, and on the recent fix on Media Preview feature of "Instant View" attachments: https://github.com/telegramdesktop/tdesktop/commit/eaaa704fa... (3 days ago)
so potentially could be just to send an Instant View link pointing to an executable app instead of a website.
for some reason, lots of people consider it to be a similar sort of thing to Signal, but it's not - Signal takes privacy and security extremely seriously, Telegram ... does not.