Skip to content
THREATWIRE

CVE

HighPoC Available

CVE-2026-107181

Telegram Desktop IPC record injection leading to local file exfiltration

Telegram Desktop before 7.2.9 does not escape the record separator in its single-instance IPC, so one click on a crafted external link can inject an extra command that reaches a legacy internal helper and sends local files, including session data, to an attacker chat. CVSS 4.0 8.6 (VulnCheck). Fixed in 7.2.9. Public PoC write-up exists. Not in CISA KEV.

CVSS
8.6
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Class
Info disclosure
Status
PoC Available
KEV
Not in CISA KEV
0-day
No
Vendor
Telegram
Products
Telegram Desktop
Affected
All versions before 7.2.9, per the VulnCheck CVE record (CPE telegram_desktop versionEndExcluding 7.2.9). The researcher confirmed the chain on Windows (tested 6.9.3) and states through 7.2.8.
Fixed
7.2.9 and later (commit db3405699f, 16 September 2026; release published 17 September 2026).
Published
7 Oct 2026
Updated
9 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2026-107181 is a record-delimiter injection (CWE-143) in Telegram Desktop's single-instance inter-process communication. When a link is opened from outside the app, Telegram Desktop passes it to the already-running instance over a local channel that separates records with a delimiter it did not escape. A crafted link can therefore carry an extra command into that channel. In the chain described by the researcher, the injected command reaches a legacy internal helper, originally meant for release publishing, that reads a local file and sends it to a chat with no authorization check and no confirmation prompt. The result is arbitrary local file read and exfiltration, including Telegram's session data, which can lead to account takeover when no local passcode is set.

VulnCheck, the CNA, published the record on 7 October 2026 and scores it CVSS 4.0 8.6 (High) with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N. It also publishes CVSS 3.1 8.1 (High), CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N, which matches the researcher's own score. The 8.6 and 8.1 figures are two CVSS versions from the same scorer, not a disagreement. NVD lists the record as Awaiting Analysis with no NVD score of its own. The affected range in the CVE record is all versions before 7.2.9; 7.2.9 is unaffected.

The fix is commit db3405699f (16 September 2026), shipped in 7.2.9, published on 17 September 2026. It removes the legacy helper, escapes the separator on the IPC channel, and adds extra hardening for mixed records on the same connection. The 7.2.9 changelog mentions only a rendering fix, and Telegram has published no security advisory. The researcher reported the issue through ZDI on 25 June 2026; the vendor fixed it independently, and ZDI closed the case as already fixed on 30 September.

The attack needs one click on a link opened outside Telegram, for example in a browser, which may ask for confirmation before launching the app. Links clicked inside Telegram are handled in-process and are not affected. The researcher's chain also relies on default settings: automatic file download in groups and the default ability for anyone to add the user to a group.

Researcher beaksec published a technical write-up on 3 October 2026 (updated 7 October) with a step-by-step proof of concept on Windows. ThreatWire did not run it. Availability is therefore PoC. CISA's ADP SSVC entry sets exploitation to poc. The CVE is not in the CISA KEV catalog, and ThreatWire found no reports of exploitation. This record does not reproduce links, file formats, paths, or steps from the write-up.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-107181