# Telegram Desktop Flaw Could Allow Account Takeover Under Conditions

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/28857
Published: 2026-10-09T10:05:46.000Z
Updated: 2026-10-09T10:05:46.000Z
Section: Technology

> CVE-2026-107181 affected version 7.2.8 and earlier. Telegram fixed the vulnerability in version 7.2.9, released Sept. 17.

A high-severity vulnerability in Telegram Desktop version 7.2.8 and earlier could allow account takeover under certain conditions, including the theft of a session file from a user without a local password.

The flaw, tracked as CVE-2026-107181, involved placing a command file in a group and persuading a victim to open a link redirected through a browser. The process could enable command injection between applications and allow local files to be sent to a group controlled by an attacker.

An attacker would need to obtain the victim’s session file for an account takeover to occur. Accounts without a local password were exposed to that risk under the described conditions.

Telegram fixed the vulnerability in Desktop version 7.2.9, released Sept. 17. Versions 7.2.8 and earlier were affected.
