Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover. | |
| Title | Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via interpret: Scheme | |
| First Time appeared |
Telegram
Telegram telegram Desktop |
|
| Weaknesses | CWE-143 | |
| CPEs | cpe:2.3:a:telegram:telegram_desktop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Telegram
Telegram telegram Desktop |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-07T17:04:52.514Z
Reserved: 2026-10-07T13:01:39.479Z
Link: CVE-2026-107181
No data.
Status : Awaiting Analysis
Published: 2026-10-07T14:17:08.807
Modified: 2026-10-07T17:16:53.520
Link: CVE-2026-107181
No data.
OpenCVE Enrichment
Updated: 2026-10-07T15:45:06Z