Telegram Desktop IPC Record-Separator Injection
Telegram Desktop versions prior to 7.2.9 contain an IPC record-separator injection vulnerability in the Core::Sandbox component, allowing remote attackers to exfiltrate local session data via crafted tg:// links.
CVE search metadata
CVE search record: CVE-2026-107181. Severity: high. CVSS: 8.1. KEV: no. Product: Telegram Desktop (< 7.2.9). Brief: Telegram Desktop IPC Record-Separator Injection. Brief link: https://feed.craftedsignal.io/briefs/2026-10-telegram-ipc-injection/
Telegram Desktop versions prior to 7.2.9 contain an IPC record-separator injection vulnerability within the Core::Sandbox component. This vulnerability is triggered when a user interacts with a specially crafted tg:// URI containing unescaped semicolons. By exploiting this flaw, an attacker can bypass IPC security boundaries to reach the interpret: scheme handler. This allows the attacker to force the application to read and upload local files, specifically targeting critical tdata session keys. If successful, this exfiltration leads to a complete account takeover, as the attacker can use the stolen session data to impersonate the victim. The attack is particularly dangerous because it relies on user-triggered URI handling, which is a common mechanism for cross-application communication in modern desktop environments.
Impact
Successful exploitation of CVE-2026-107181 results in full account takeover for users of Telegram Desktop. By exfiltrating tdata session keys, attackers gain unauthorized access to the victim's Telegram account, enabling them to read private messages, impersonate the user, and potentially propagate further malicious links or malware through the victim's existing contact list.
Recommendation
Update all Telegram Desktop installations to version 7.2.9 or later immediately. Ensure that browser and OS-level URI handlers are monitored for unexpected or repetitive attempts to trigger tg:// links, particularly those containing encoded characters or unusual parameters.
Mitigations
Upgrade Telegram Desktop to version 7.2.9 or later.
CVE-2026-107181