Telegram Desktop CVE-2026-107181 (CVSS 4.0 8.6): one click on a crafted tg:// link opened outside the app could send local files, including session data, to an attacker chat; fixed in 7.2.9
VulnCheck assigned CVE-2026-107181 on 7 October 2026 to a flaw in Telegram Desktop before 7.2.9 that researcher beaksec described in a technical write-up first published on 3 October and updated on 7 October. When a link is opened from outside Telegram (for example from a browser), a second instance passes it to the running app over a local inter-process channel that did not escape its record separator (CWE-143). A crafted tg:// link with an unescaped semicolon could therefore inject an extra command that reached an old internal helper, once used for release publishing, which uploads a local file to a chat without any permission check or prompt. Files that can be taken include Telegram's tdata session keys, so an attacker can take over the account when no local passcode is set. The demonstrated chain was on Windows with version 6.9.3 and is said to work through 7.2.8; it also relies on group files downloading automatically and on anyone being able to add the victim to a group, and the browser may ask before launching the app. Links clicked inside Telegram are not affected. Telegram fixed it in commit db3405699f (16 September) and released 7.2.9 on 17 September 2026 without a separate advisory; CVSS 3.1 is 8.1. No exploitation in the wild is known. Primary: CVE record (VulnCheck) and Telegram's fix; wires: ThreatWire, Cyber Security News.
- Product
- Telegram Desktop (tdesktop) — single-instance IPC / external link handling
- Versions
- before 7.2.9 (write-up: confirmed on 6.9.3 for Windows, present through 7.2.8)
- CVSS
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N- Exploited in Australia?
- unknown
- Patch to
- Update Telegram Desktop to 7.2.9 or later, set a local passcode, and consider turning off automatic file downloads in groups and limiting who can add you to groups.
Primary: NVD — CVE-2026-107181 (CNA VulnCheck, published 7 Oct 2026) · Vendor: Telegram Desktop — v7.2.9 release (fix commit db3405699f) · CVE: CVE-2026-107181 · ThreatWire — Telegram Desktop one-click file theft is CVE-2026-107181; also Cyber Security News (9 Oct 2026)
