CVE-2026-107181

CVE-2026-107181 published: Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme h...

View full NVD advisory → ← Back to CVE watch