Telegram Desktop Link Flaw Fixed in Version 7.2.9
Telegram Desktop before 7.2.9 can leak local files via a crafted link; version 7.2.9 fixes CVE-2026-107181.
Two October 9, 2026 reports describe CVE-2026-107181 in Telegram Desktop before 7.2.9, where a crafted link can cause the app to read local files and send them to a chat, including session data when no local passcode is set, enabling account takeover. Cyber Security News attributes a public proof of concept to researcher Beaksec, classifies the flaw as CWE-143 unescaped IPC record delimiters, and says the chain also depends on auto-downloads and open group invites. Lobsters describes an unescaped semicolon in local IPC messages reached through a tg:// link and states that the victim must click the link. Both sources agree on a CVSS 3.1 score of 8.1, while only Cyber Security News also cites CVSS 4.0 at 8.6. Demonstration details differ in specificity: one source says Windows through 7.2.8 was shown and macOS and Linux were not, while the other says Windows build 6.9.3 was confirmed. Telegram fixed the issue in version 7.2.9 on September 17, 2026, and Cyber Security News reported no known exploitation or CISA KEV listing as of October 9.
- CVE-2026-107181 affects Telegram Desktop before 7.2.9 (through 7.2.8).
- Cyber Security News scores it 8.6 on CVSS 4.0 and 8.1 on CVSS 3.1; Lobsters reports CVSS 3.1 8.1 High.
- A clicked crafted link can reach a legacy helper that reads local files, including session data if no local passcode is set, and sends them to a chat.
- Cyber Security News says the chain also needs auto-downloads and open group invites and classifies it as CWE-143; Lobsters cites an unescaped semicolon in local IPC messages via a tg:// link.
- Beaksec demonstrated the issue on Windows through 7.2.8, with macOS and Linux not shown; Lobsters says it was confirmed on Windows build 6.9.3.
- Telegram fixed it in desktop version 7.2.9 on September 17, 2026, by removing the helper.
- As of October 9, 2026, Cyber Security News reported no known exploitation and no CISA KEV listing.
Coverage timelineoldest first · each row is one article
- · 1d agoPoC Released for Telegram Desktop Flaw Enabling One-Click File Account Takeover
Cyber Security News· 64
Public PoC shows Telegram Desktop before 7.2.9 can leak local files and sessions via a crafted link.
- · 1d agoTelegram Desktop: one-click account takeover via IPC injection
Lobsters · security· 66
Telegram Desktop through 7.2.8 let a clicked link steal local login files.
Vulnerabilities in this storyAll →
- CVE-2026-1071818.6<1%IPC record injection in Telegram Desktop enables account takeoverpublished · Telegram Desktop PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-107181 | IPC record injection in Telegram Desktop enables account takeover |