CVE-2026-107181 - Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via interpret: Scheme
CVE ID :CVE-2026-107181 Published : Oct. 7, 2026, 2:17 p.m. | 1 hour, 12 minutes ago Description :Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing...