CVE-2026-107181
Awaiting Analysis Awaiting Analysis - Queue

Telegram Desktop IPC Record-Separator Injection via tg:// Links

Vulnerability report for CVE-2026-107181, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: VulnCheck

Description

Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Telegram Telegram Desktop 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-143 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as record delimiters when they are sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Telegram Desktop before version 7.2.9 has a vulnerability where attackers can inject IPC records via crafted tg:// links containing unescaped semicolons. This allows them to exploit the interpret: scheme handler to upload local files, including sensitive session keys, to an attacker-controlled channel, potentially leading to account takeover.

Detection Guidance

Detecting this vulnerability requires checking the installed version of Telegram Desktop. Run 'Telegram --version' or check the application's 'About' section. If the version is below 7.2.9, the system is vulnerable. Additionally, monitor network traffic for suspicious tg:// or interpret: scheme requests containing semicolons or unusual file paths.

Impact Analysis

If exploited, this vulnerability could allow attackers to steal your Telegram session files and encryption keys, enabling them to take over your account without your knowledge. Victims only need to click a malicious link for the attack to succeed.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating privacy regulations like GDPR and HIPAA. Organizations using vulnerable Telegram versions may face compliance breaches due to potential data exfiltration.

Mitigation Strategies

Immediately upgrade Telegram Desktop to version 7.2.9 or later. Disable automatic file downloads in settings to prevent unauthorized file exfiltration. Restrict who can add you to groups or channels to reduce exposure to malicious links.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107181. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart