{"id":"CVE-2026-107181","title":"Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons","summary":"Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","cwe":["CWE-143"],"vendor":"Telegram","product":"Telegram Desktop","affected":["desktop < 7.2.9"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T14:17:08.807","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107181","references":[{"url":"https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/","label":"disclosure@vulncheck.com"},{"url":"https://github.com/telegramdesktop/tdesktop","label":"disclosure@vulncheck.com"},{"url":"https://github.com/telegramdesktop/tdesktop/blob/v7.2.8/Telegram/SourceFiles/core/sandbox.cpp#L362-L364","label":"disclosure@vulncheck.com"},{"url":"https://github.com/telegramdesktop/tdesktop/blob/v7.2.8/Telegram/SourceFiles/support/support_helper.cpp#L673-L751","label":"disclosure@vulncheck.com"},{"url":"https://github.com/telegramdesktop/tdesktop/commit/db3405699f8fc3ae28a58d2348b7d13a43c0590a","label":"disclosure@vulncheck.com"},{"url":"https://github.com/telegramdesktop/tdesktop/releases/tag/v7.2.9","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/telegram-desktop-before-7.2.9-ipc-record-injection-file-exfiltration-via-interpret-scheme","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-07T14:33:21.951Z","slug":"CVE-2026-107181","body":"## Overview\n\nTelegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}