CVE-2026-107181: Telegram Desktop

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.

Affected products

  • Telegram Telegram Desktop: before 7.2.9 (fixed in 7.2.9)

Published 2026-10-07. Last modified 2026-10-07.