{"id":"CVE-2026-107181","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-107181","summary":"Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via interpret: Scheme","details":"Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.","published":"2026-10-07T13:35:40.907Z","modified":"2026-10-08T07:09:20.638854759Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/telegramdesktop/tdesktop/commit/db3405699f8fc3ae28a58d2348b7d13a43c0590a","label":"telegramdesktop/tdesktop@db34056"},"references":[{"type":"EVIDENCE","url":"https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107181.json"},{"type":"PACKAGE","url":"https://github.com/telegramdesktop/tdesktop"},{"type":"ARTICLE","url":"https://github.com/telegramdesktop/tdesktop/blob/v7.2.8/Telegram/SourceFiles/core/sandbox.cpp#L362-L364"},{"type":"ARTICLE","url":"https://github.com/telegramdesktop/tdesktop/blob/v7.2.8/Telegram/SourceFiles/support/support_helper.cpp#L673-L751"},{"type":"FIX","url":"https://github.com/telegramdesktop/tdesktop/commit/db3405699f8fc3ae28a58d2348b7d13a43c0590a"},{"type":"ADVISORY","url":"https://github.com/telegramdesktop/tdesktop/releases/tag/v7.2.9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107181"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/telegram-desktop-before-7.2.9-ipc-record-injection-file-exfiltration-via-interpret-scheme"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-08T07:09:20.638854759Z"}}