8.6

CVE-2026-107181

Exploit

Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via interpret: Scheme

Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTelegram
≫
Produkt Telegram Desktop
Default Statusunaffected
Version 0
Version < 7.2.9
Status affected
Version 7.2.9
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.26
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosure@vulncheck.com 8.6 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
disclosure@vulncheck.com 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CWE-143 Improper Neutralization of Record Delimiters

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as record delimiters when they are sent to a downstream component.

https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
https://github.com/telegramdesktop/tdesktop/commit/db3405699f8fc3ae28a58d2348b7d13a43c0590a
https://github.com/telegramdesktop/tdesktop/releases/tag/v7.2.9
https://github.com/telegramdesktop/tdesktop/blob/v7.2.8/Telegram/SourceFiles/core/sandbox.cpp#L362-L364
https://github.com/telegramdesktop/tdesktop/blob/v7.2.8/Telegram/SourceFiles/support/support_helper.cpp#L673-L751
https://github.com/telegramdesktop/tdesktop
https://www.vulncheck.com/advisories/telegram-desktop-before-7.2.9-ipc-record-injection-file-exfiltration-via-interpret-scheme