<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:telegram:telegram_desktop:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3atelegramtelegram_desktop/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 14:37:32 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3atelegramtelegram_desktop/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Telegram Desktop IPC Record-Separator Injection</title><link>https://feed.craftedsignal.io/briefs/2026-10-telegram-ipc-injection/</link><pubDate>Wed, 07 Oct 2026 14:37:32 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-telegram-ipc-injection/</guid><description>Telegram Desktop versions prior to 7.2.9 contain an IPC record-separator injection vulnerability in the Core::Sandbox component, allowing remote attackers to exfiltrate local session data via crafted tg:// links.</description><content:encoded><![CDATA[<p>Telegram Desktop versions prior to 7.2.9 contain an IPC record-separator injection vulnerability within the Core::Sandbox component. This vulnerability is triggered when a user interacts with a specially crafted tg:// URI containing unescaped semicolons. By exploiting this flaw, an attacker can bypass IPC security boundaries to reach the interpret: scheme handler. This allows the attacker to force the application to read and upload local files, specifically targeting critical tdata session keys. If successful, this exfiltration leads to a complete account takeover, as the attacker can use the stolen session data to impersonate the victim. The attack is particularly dangerous because it relies on user-triggered URI handling, which is a common mechanism for cross-application communication in modern desktop environments.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-107181 results in full account takeover for users of Telegram Desktop. By exfiltrating tdata session keys, attackers gain unauthorized access to the victim's Telegram account, enabling them to read private messages, impersonate the user, and potentially propagate further malicious links or malware through the victim's existing contact list.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update all Telegram Desktop installations to version 7.2.9 or later immediately. Ensure that browser and OS-level URI handlers are monitored for unexpected or repetitive attempts to trigger tg:// links, particularly those containing encoded characters or unusual parameters.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>ipc</category><category>exfiltration</category></item></channel></rss>