CVE-2026-107181

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-143

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-07: 110-07
Referenced assets1 URL
Full discourse1 post
  • Hephaestvs@Vulcanux_

    csirt_it: ‼️ #PoC #Telegram: disponibile Proof of Concept (PoC) per la vulnerabilità CVE-2026-107181 Rischio: 🔴 Tipologia: 🔸 Arbitrary File Read 🔸 Information Disclosure 🔸 Authentication Bypass 🔗 https://www.acn.gov.it/portale/w/telegram-desktop-poc-pubblica-per-lo-sfruttamento-della-cve-2026-107181 ⚠️ Importante mantenere a… https://t.co/G3x8dZiNLX

    0000047
    643 followersView on X

Explore more