1 min read
Add as a preferred source on Google

Telegram Desktop Flaw Could Allow Account Takeover Under Conditions

CVE-2026-107181 affected version 7.2.8 and earlier. Telegram fixed the vulnerability in version 7.2.9, released Sept. 17.

Laptop beside a USB drive under muted evening light / TokenPost.ai
Laptop beside a USB drive under muted evening light / TokenPost.ai

A high-severity vulnerability in Telegram Desktop version 7.2.8 and earlier could allow account takeover under certain conditions, including the theft of a session file from a user without a local password.

The flaw, tracked as CVE-2026-107181, involved placing a command file in a group and persuading a victim to open a link redirected through a browser. The process could enable command injection between applications and allow local files to be sent to a group controlled by an attacker.

An attacker would need to obtain the victim’s session file for an account takeover to occur. Accounts without a local password were exposed to that risk under the described conditions.

Telegram fixed the vulnerability in Desktop version 7.2.9, released Sept. 17. Versions 7.2.8 and earlier were affected.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…