Vulnerability intelligence
CVE-2026-107181
Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.
CVSS Score
8.6
High
EPSS — Exploit Probability
0.3%
Riskier than 26% of all CVEs · checked 2026-10-09
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Oct 9, 2026 · latest Oct 9, 2026
Coverage timeline
-
Telegram Desktop flaw lets attackers steal session keys with one clicksecurityonline.info · Oct 9, 2026