#1150328 telegram-desktop: CVE-2026-107181

Package:
src:telegram-desktop
Source:
src:telegram-desktop
Submitter:
Moritz Mühlenhoff
Date:
2026-10-08 18:45:03 UTC
Severity:
normal
Tags:
#1150328#5
Date:
2026-10-08 17:31:03 UTC
From:
To:
Hi,

The following vulnerability was published for telegram-desktop.

CVE-2026-107181[0]:
| Telegram Desktop before 7.2.9 contains an IPC record-separator
| injection vulnerability in Core::Sandbox that allows remote
| attackers to inject OPEN: records via crafted tg:// links containing
| unescaped semicolons. Attackers can reach the interpret: scheme
| handler to upload local files, including tdata session keys, to an
| attacker channel, enabling account takeover.

https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
https://github.com/telegramdesktop/tdesktop/commit/db3405699f8fc3ae28a58d2348b7d13a43c0590a (v7.2.9)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-107181
https://www.cve.org/CVERecord?id=CVE-2026-107181

Please adjust the affected versions in the BTS as needed.