CPE
Telegram Desktop versions prior to 7.2.9 contain an IPC record-separator injection vulnerability in the Core::Sandbox component, allowing remote attackers to exfiltrate local session data via crafted tg:// links.