CVE-2026-107181
HIGH
NVD
CVSS Score
8.1
Severity
HIGH
Published
Oct 07, 2026
Vendor
unknown
Description
Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.
References
- https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
- https://github.com/telegramdesktop/tdesktop
- https://github.com/telegramdesktop/tdesktop/blob/v7.2.8/Telegram/SourceFiles/core/sandbox.cpp#L362-L364
- https://github.com/telegramdesktop/tdesktop/blob/v7.2.8/Telegram/SourceFiles/support/support_helper.cpp#L673-L751
- https://github.com/telegramdesktop/tdesktop/commit/db3405699f8fc3ae28a58d2348b7d13a43c0590a