Hi,
The following vulnerability was published for telegram-desktop.
CVE-2026-107181[0]:
| Telegram Desktop before 7.2.9 contains an IPC record-separator
| injection vulnerability in Core::Sandbox that allows remote
| attackers to inject OPEN: records via crafted tg:// links containing
| unescaped semicolons. Attackers can reach the interpret: scheme
| handler to upload local files, including tdata session keys, to an
| attacker channel, enabling account takeover.
https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
https://github.com/telegramdesktop/tdesktop/commit/db3405699f8fc3ae28a58d2348b7d13a43c0590a (v7.2.9)
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-107181
https://www.cve.org/CVERecord?id=CVE-2026-107181
Please adjust the affected versions in the BTS as needed.