Telegram Desktop 7.2.9 fixes CVE-2026-107181 account session theft
A vulnerability in Telegram Desktop up to version 7.2.8, tracked as CVE-2026-107181, let an attacker steal an active account session with a single click on a link in a chat. The flaw chained an IPC command injection with the internal interpret: scheme, enabling local file reads and exfiltration without confirmation. The fix shipped in version 7.2.9 (commit db3405699f); CVSS 3.1 score is 8.1.
- CVE-2026-107181: one click on a chat link stole a Telegram Desktop session
- Affected versions up to 7.2.8, including Windows build 6.9.3
- CVSS 3.1 score 8.1: remote, no privileges, but requires user click
- Patched in 7.2.9 via commit db3405699f
Read next
Security