chiprook
← Security
SecurityOctober 10, 2026, 21:31

Telegram Desktop 7.2.9 fixes CVE-2026-107181 account session theft

A vulnerability in Telegram Desktop up to version 7.2.8, tracked as CVE-2026-107181, let an attacker steal an active account session with a single click on a link in a chat. The flaw chained an IPC command injection with the internal interpret: scheme, enabling local file reads and exfiltration without confirmation. The fix shipped in version 7.2.9 (commit db3405699f); CVSS 3.1 score is 8.1.

Telegram Desktop 7.2.9 fixes CVE-2026-107181 account session theft
#Telegram
Read next
Security

Claude and ChatGPT sessions sold for $5 on Telegram after infostealer theft

Security

Group-IB: Telegram Account Behind ASOS Rogue Notification Tied to Gaming Trading

Security

Ghost Service Accounts Enable M365 Data Theft in Chile

Security

Belarusian hacktivists spent two years inside Russian healthcare network