Index
Search
Search the public record. Drafts and scheduled notes are not included.
High
research
Telegram Desktop one-click file theft is CVE-2026-107181
A researcher write-up shows how one click on a crafted external link could make Telegram Desktop before 7.2.9 send local files, including session data, to an attacker chat. CVSS 4.0 8.6 (VulnCheck). Fixed in 7.2.9 without a vendor advisory. Public PoC write-up exists. Not in CISA KEV; no known exploitation.
Published 2h ago
HighPoC Available
CVE-2026-107181
Telegram Desktop IPC record injection leading to local file exfiltration
Info disclosure
Published 2d ago