CVE-2026-107181 debrief: Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via interpret: Scheme. This CVE record describes a vulnerability in Telegram Desktop before version 7.2.9, where an IPC record-separator injection vulnerability in Core::Sandbox allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpr [truncated]
A disputed null pointer dereference vulnerability in Telegram Desktop up to version 6.7.5, affecting the RequestButton function in url_auth_box.cpp. The issue involves manipulation of the login_url argument in the Bot API component. The vendor disputes this constitutes a security vulnerability, characterizing it as a one-time crash requiring user interaction with no persistent effects. The CVE was publish [truncated]