OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-107181 (CVSS 8.6)

NVD · officialPublished Oct 7, 2026Risk 37/100

Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.

CVSS
8.6
AV:NetworkAC:LowPR:NoneUI:Passive

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source