# PoC Released for Telegram Desktop One-Click Flaw Enabling File Access / Account Takeover (CVE-2026-107181)

> A public PoC by researcher Beaksec (Emiliano Versini) shows that Telegram Desktop before 7.2.9 fails to escape the record separator (semicolon) in its single-instance IPC, letting a crafted tg:// link inject OPEN: records that reach a legacy interpret: release-publishing helper. The helper reads arbitrary local files, including tdata session files, and uploads them to an attacker channel, enabling account takeover. Fixed in 7.2.9; no confirmed in-the-wild exploitation or CISA KEV listing as of 2026-10-09.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3119
- **ID:** TL-2026-3119
- **Severity:** HIGH (CVSS 8.6)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 7 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-107181

## Description

CVE-2026-107181 (CWE-143, Improper Neutralization of Record Delimiters) is an IPC record-separator injection in Core::Sandbox of Telegram Desktop through 7.2.8. Telegram Desktop hands links opened outside the app (for example from a browser) to its already-running instance over a local socket, as text, using a semicolon-delimited record format such as OPEN:tg://x?a=1;. The separator is never escaped, so a link like tg://x?a=1;OPEN:interpret:<path> is split into several records and the injected records are processed as if the user had requested them.

The injected records reach a second defect: an internal interpret: URI scheme handler (support_helper.cpp) that was built for automated release publishing. It reads an instruction text file with channel:, file: and caption: fields and then reads any file on disk and sends it to the named chat, without user confirmation and without checking who asked. The from: verification field is optional and is skipped when omitted. Relative paths resolve from the Telegram data directory (%APPDATA%\Telegram Desktop), so interpret:../../../Downloads/Telegram%20Desktop/<file> reaches files that Telegram has auto-downloaded.

The PoC chain, tested on Windows against versions 6.9.3 to 7.2.8, works as follows. (1) The attacker creates a supergroup, adds the victim (default privacy settings permit this) and posts three instruction text files, which are auto-downloaded (group files up to 8 MiB) to C:\Users\<user>\Downloads\Telegram Desktop\. (2) The attacker posts an HTTPS link that redirects to tg://x?a=1;OPEN:interpret:[path1];OPEN:interpret:[path2];OPEN:interpret:[path3]. (3) The victim opens the group and clicks the link in a browser while Telegram Desktop is already running. (4) The three interpret: records upload tdata/key_datas, tdata/D877F783D5D3EF8Cs and tdata/D877F783D5D3EF8C/maps to the attacker's channel. With no local passcode set (the default), the key-encryption key derives from an empty string plus the stored salt, so these files allow the attacker to rebuild and import the victim's authorized session.

Timeline: reported via ZDI on 2026-06-25; vendor fixed independently in commit db3405699f (2026-09-16, 'Remove legacy interpret path helper'); 7.2.9 released 2026-09-17; PoC writeup published 2026-10-03 (updated 2026-10-07); CVE assigned by VulnCheck 2026-10-07. The fix percent-escapes the record separator, removes the interpret scheme, and blocks mixing external URLs with local file paths in one connection. CVSS 4.0 is 8.6 and CVSS 3.1 is 8.1. No active exploitation has been reported and no network IOCs were published.

## MITRE ATT&CK

- T1585 Establish Accounts
- T1566.002 Spearphishing Link
- T1204.001 Malicious Link
- T1203 Exploitation for Client Execution
- T1552.001 Credentials In Files
- T1528 Steal Application Access Token
- T1005 Data from Local System
- T1567 Exfiltration Over Web Service
- T1550 Use Alternate Authentication Material

## Sources

- [PoC Released for Telegram Desktop Flaw Enabling One-Click File Account Takeover](https://cybersecuritynews.com/poc-released-for-telegram-desktop-flaw/)
- [Beaksec: Telegram Desktop one-click account takeover (PoC writeup)](https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/)
- [VulnCheck Advisory: Telegram Desktop before 7.2.9 IPC record injection file exfiltration via interpret scheme](https://www.vulncheck.com/advisories/telegram-desktop-before-7.2.9-ipc-record-injection-file-exfiltration-via-interpret-scheme)
- [tdesktop fix commit db3405699f: Remove legacy interpret path helper](https://github.com/telegramdesktop/tdesktop/commit/db3405699f8fc3ae28a58d2348b7d13a43c0590a)
- [Telegram Desktop v7.2.9 release](https://github.com/telegramdesktop/tdesktop/releases/tag/v7.2.9)
- [Vulnerable IPC separator code, sandbox.cpp (v7.2.8)](https://github.com/telegramdesktop/tdesktop/blob/v7.2.8/Telegram/SourceFiles/core/sandbox.cpp#L362-L364)
- [Vulnerable interpret: handler, support_helper.cpp (v7.2.8)](https://github.com/telegramdesktop/tdesktop/blob/v7.2.8/Telegram/SourceFiles/support/support_helper.cpp#L673-L751)
- [SecurityOnline: Telegram Desktop Account Takeover PoC Disclosed](https://securityonline.info/telegram-desktop-account-takeover-poc/)
- [OpenCVE: CVE-2026-107181](https://app.opencve.io/cve/CVE-2026-107181)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3119
