CVE-2026-107181: Telegram Desktop
High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.
Affected products
- Telegram Telegram Desktop: before 7.2.9 (fixed in 7.2.9)
Published 2026-10-07. Last modified 2026-10-07.