Anyone have any info on this, how serious it is etc? Very vague post.
where you could open an app by running window.open("C:\Windows\system32\cmd.exe")
This is a guess based on the behavior in the video, and on the recent fix on Media Preview feature of "Instant View" attachments: https://github.com/telegramdesktop/tdesktop/commit/eaaa704fa... (3 days ago)
so potentially could be just to send an Instant View link pointing to an executable app instead of a website.
Disabling of automatic media parsing as suggested is absolutely a wise choice.
This would be pretty bad indeed if it were wormable.