Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover. | |
| Title | Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via interpret: Scheme | |
| First Time appeared |
Telegram
Telegram telegram Desktop |
|
| Weaknesses | CWE-143 | |
| CPEs | cpe:2.3:a:telegram:telegram_desktop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Telegram
Telegram telegram Desktop |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-07T13:35:40.907Z
Reserved: 2026-10-07T13:01:39.479Z
Link: CVE-2026-107181
No data.
Status : Awaiting Analysis
Published: 2026-10-07T14:17:08.807
Modified: 2026-10-07T16:02:27.613
Link: CVE-2026-107181
No data.
OpenCVE Enrichment
Updated: 2026-10-07T15:45:06Z
Weaknesses