> The primitive stays the same throughout: arbitrary file read. What changes is what you read: an SSH private key, a browser password store, a cloud credentials file, or a configuration holding an API token.

So in the hindsight it was a right thing for me to put it into a sandbox without any SSH keys and tokens. Also, I didn't bother registering tg:// scheme in the OS which also turned out to be good - clicking such a link in the browser does nothing for me, and as a side effect, websites cannot detect presence of Telegram or send command to it though registered scheme handler.

Also, I was surprised that Telegram uses passcode (an on-device password that is required to access the app) to encrypt user data. I thought they just keep the hash of a passcode and check it.

Also I assume Telegram can block this attack on the server, as groups are not E2EE and the server can find and delete files needed for successful exploitation. And links too. If someone has a spare account they can check if posting such type of files or links works.