Threat reportVulnerabilityTL-2026-3119
PoC Released for Telegram Desktop One-Click Flaw Enabling File Access / Account Takeover (CVE-2026-107181)
PoC Released for Telegram Desktop One-Click Flaw Enabling (TL-2026-3119) is a high-severity software vulnerability scored CVSS 8.6, first published 2026-10-09. It has no confirmed attribution, affects Telegram Telegram Desktop, references 1 CVE (CVE-2026-107181), maps to 9 MITRE ATT&CK techniques (T1005, T1203, T1204.001), and is covered by 9 detection rules and 7 indicators of compromise.
- CVSS
- 8.6/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 9MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 7Indicators of compromise
Key facts for TL-2026-3119
- Threat ID
- TL-2026-3119
- Severity
- HIGH
- CVSS
- 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, government administration, finance, news - media, cryptocurrency
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 7
Malware and tooling in PoC Released for Telegram Desktop One-Click Flaw Enabling
Malware and tooling: telegram
How PoC Released for Telegram Desktop One-Click Flaw Enabling works
A public PoC by researcher Beaksec (Emiliano Versini) shows that Telegram Desktop before 7.2.9 fails to escape the record separator (semicolon) in its single-instance IPC, letting a crafted tg:// link inject OPEN: records that reach a legacy interpret: release-publishing helper. The helper reads arbitrary local files, including tdata session files, and uploads them to an attacker channel, enabling account takeover. Fixed in 7.2.9; no confirmed in-the-wild exploitation or CISA KEV listing as of 2026-10-09.
CVE-2026-107181 (CWE-143, Improper Neutralization of Record Delimiters) is an IPC record-separator injection in Core::Sandbox of Telegram Desktop through 7.2.8. Telegram Desktop hands links opened outside the app (for example from a browser) to its already-running instance over a local socket, as text, using a semicolon-delimited record format such as OPEN:tg://x?a=1;. The separator is never escaped, so a link like tg://x?a=1;OPEN:interpret:<path> is split into several records and the injected records are processed as if the user had requested them.
The injected records reach a second defect: an internal interpret: URI scheme handler (support_helper.cpp) that was built for automated release publishing. It reads an instruction text file with channel:, file: and caption: fields and then reads any file on disk and sends it to the named chat, without user confirmation and without checking who asked. The from: verification field is optional and is skipped when omitted. Relative paths resolve from the Telegram data directory (%APPDATA%\Telegram Desktop), so interpret:../../../Downloads/Telegram%20Desktop/<file> reaches files that Telegram has auto-downloaded.
The PoC chain, tested on Windows against versions 6.9.3 to 7.2.8, works as follows. (1) The attacker creates a supergroup, adds the victim (default privacy settings permit this) and posts three instruction text files, which are auto-downloaded (group files up to 8 MiB) to C:\Users\<user>\Downloads\Telegram Desktop\. (2) The attacker posts an HTTPS link that redirects to tg://x?a=1;OPEN:interpret:[path1];OPEN:interpret:[path2];OPEN:interpret:[path3]. (3) The victim opens the group and clicks the link in a browser while Telegram Desktop is already running. (4) The three interpret: records upload tdata/key_datas, tdata/D877F783D5D3EF8Cs and tdata/D877F783D5D3EF8C/maps to the attacker's channel. With no local passcode set (the default), the key-encryption key derives from an empty string plus the stored salt, so these files allow the attacker to rebuild and import the victim's authorized session.
Timeline: reported via ZDI on 2026-06-25; vendor fixed independently in commit db3405699f (2026-09-16, 'Remove legacy interpret path helper'); 7.2.9 released 2026-09-17; PoC writeup published 2026-10-03 (updated 2026-10-07); CVE assigned by VulnCheck 2026-10-07. The fix percent-escapes the record separator, removes the interpret scheme, and blocks mixing external URLs with local file paths in one connection. CVSS 4.0 is 8.6 and CVSS 3.1 is 8.1. No active exploitation has been reported and no network IOCs were published.
MITRE ATT&CK techniques used in TL-2026-3119
Collection
Execution
T1203 Exploitation for Client Execution; T1204.001 Malicious Link
Credential Access
T1528 Steal Application Access Token; T1552.001 Credentials In Files
lateral-movement
T1550 Use Alternate Authentication Material
Initial Access
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Affected products and versions in PoC Released for Telegram Desktop One-Click Flaw Enabling
- Telegram — Telegram Desktop
Vulnerable versions: < 7.2.9 (PoC tested on Windows 6.9.3 to 7.2.8)
Fixed in: 7.2.9
Remediation for PoC Released for Telegram Desktop One-Click Flaw Enabling
Patches
- Telegram Desktop 7.2.9 (fix commit db3405699f8fc3ae28a58d2348b7d13a43c0590a)
Immediate actions
- Update Telegram Desktop to 7.2.9 or later
- Review group chats for unexpected instruction text files and unexpected file uploads from your account
- If compromise is suspected, terminate unknown active sessions in Telegram and re-authenticate
Workarounds
- Enable 'ask where to save each file' to disable automatic group file downloads
- Restrict who can add you to groups to contacts only
- Do not click external links posted in unsolicited groups while Telegram Desktop is running
Longer-term hardening
- Set a local passcode so tdata session files are encrypted with a non-empty key
- Inventory and enforce a minimum Telegram Desktop version on managed endpoints
CVEs associated with PoC Released for Telegram Desktop One-Click Flaw Enabling
Weaknesses (CWE) in PoC Released for Telegram Desktop One-Click Flaw Enabling
Timeline of PoC Released for Telegram Desktop One-Click Flaw Enabling
- Vulnerability reported through the Zero Day Initiative (ZDI)
- Telegram fixes the issue independently in commit db3405699f ('Remove legacy interpret path helper'), removing the interpret scheme and escaping the IPC separator
- Telegram Desktop 7.2.9 released with the fix
- Beaksec publishes the full writeup and PoC for the one-click account takeover chain
- VulnCheck assigns CVE-2026-107181 (CWE-143, CVSS 4.0 8.6 / CVSS 3.1 8.1); writeup updated the same day
- Cyber Security News reports the public PoC; no confirmed in-the-wild exploitation and no CISA KEV listing identified
Sources cited for PoC Released for Telegram Desktop One-Click Flaw Enabling
- PoC Released for Telegram Desktop Flaw Enabling One-Click File Account Takeover
- Beaksec: Telegram Desktop one-click account takeover (PoC writeup)
- VulnCheck Advisory: Telegram Desktop before 7.2.9 IPC record injection file exfiltration via interpret scheme
- tdesktop fix commit db3405699f: Remove legacy interpret path helper
- Telegram Desktop v7.2.9 release
- Vulnerable IPC separator code, sandbox.cpp (v7.2.8)
- Vulnerable interpret: handler, support_helper.cpp (v7.2.8)
- SecurityOnline: Telegram Desktop Account Takeover PoC Disclosed
- OpenCVE: CVE-2026-107181
Detection coverage for TL-2026-3119
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3119 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.