Researchers disclosed a class of one-click remote code execution flaws in desktop applications that passed user-controlled URLs to the operating system without tightly restricting URI schemes or destinations. The issue affected multiple widely used clients, including Nextcloud, Telegram Desktop, VLC, OpenOffice, LibreOffice, Mumble, Wireshark, and several Bitcoin-derived wallets, where a single click on a crafted link could trigger unsafe URI handlers, auto-mount remote shares, or launch attacker-controlled content depending on the operating system and desktop environment. The researchers said exploitation was shaped by platform behavior, and warned that application-level fixes alone were not enough without changes in operating systems and frameworks such as Qt.
A related case showed how the same pattern led to practical exploitation in Keybase on Windows, where specially formatted chat links could display benign text while pointing to arbitrary URI targets. In that scenario, attacker-controlled payment-request content using Lumens (XLM) could be turned into clickable links that executed local or SMB-hosted programs when clicked, creating a viable one-click RCE path. Vendors responded with a mix of mitigations, including restricting allowed schemes, adding warnings, changing URL-opening behavior, removing separate display fields, and forcing non-HTTP(S) links to be prefixed safely, although some products were still awaiting fixes at the time of disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Positive Security published research describing a class of one-click code execution vulnerabilities in desktop applications that pass user-controlled URLs to the operating system without sufficiently restricting URI schemes or destinations. The write-up identified affected applications including Nextcloud, Telegram Desktop, VLC, OpenOffice, LibreOffice, Mumble, Bitcoin-derived wallets, and Wireshark, and noted that several vendors had patched while some products remained vulnerable.
Shielder reported a one-click remote code execution issue in Keybase chat clients on Windows caused by unsafe handling of specially formatted link objects. The vendor fixed the issue by removing the separate display field and forcing non-HTTP(S) URLs to be prefixed with http://, blocking the RCE path.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.