A public proof-of-concept for CVE-2026-107181 dropped October 9, and if your Telegram Desktop is running anything before version 7.2.9, you are already in the exploit window. One crafted link — clicked outside the app in a browser — sends your session files to an attacker-controlled Telegram channel. No prompts, no warnings, no 2FA bypass required. The patch shipped September 17. The official changelog called it a “rendering fix.” Most users had no idea a session-key thief was public until this week.
What Happens When You Click
The attack works through Telegram Desktop’s inter-process communication (IPC) layer. When you click an https:// link outside the app, a server responds with a 302 redirect to a crafted tg:// URL. Telegram Desktop receives the URL over its local IPC socket, where it parses commands separated by semicolons.
The flaw: Telegram never escaped semicolons in the URL before parsing. A URL like tg://x?a=1;interpret:../tdata/key_datas arrives as one string but parses as two commands. The injected second command activates a legacy file handler called InterpretSendPath, which reads local files and uploads them to a chat with zero authorization checks.
Three files get exfiltrated: key_datas (session salt and wrapped encryption key), the MTProto authorization credentials, and the session index. Drop those three files into a fresh tdata folder on any machine and you have full account access. It is the exact equivalent of stealing a browser session cookie — no password, no 2FA, just complete access.
Four Flaws Chained Together
This is not a single bug. Researcher Beaksec documented four independent failures that combine into a critical chain according to the VulnCheck CVE-2026-107181 advisory:
- Unescaped IPC delimiter — semicolons in URLs are not escaped before the IPC protocol parses them, enabling command injection
- Orphaned legacy handler — the
interpret:URI scheme, originally an internal build-workflow helper insupport_helper.cpp, was never removed. It had no authorization layer because “internal automation was the only intended user” - Relative path traversal — the handler resolves paths from the app data directory, so no victim username is needed to reach
tdata - Default encryption is obfuscation — without a local passcode set, Telegram derives the session encryption key from a salt stored in plaintext. The session data is “encrypted at rest” in name only
Telegram’s fix, commit db3405699f, addressed both symptoms: it added proper delimiter escaping via EscapeTo7bit/EscapeFrom7bit, and it deleted the legacy handler entirely. The commit message reads “Remove legacy interpret path helper” — which tells you everything. As the root cause analysis on Dev.to explains, the code path survived years of development because internal-only paths rarely get security reviews.
A Silent Patch and a 16-Day Window
Here is where Telegram’s handling deserves scrutiny. Version 7.2.9 shipped September 17 with a changelog entry that reads: “Fix some tlottie incorrect renderings.” No security advisory. No CVE reference. Nothing that would tell a user or system administrator to treat this as an urgent patch.
Researcher Beaksec published the technical disclosure October 3 — 16 days later. The public PoC repository went live October 9. That is a 22-day window between fix and PoC, during which users running 7.2.8 had no signal that anything was wrong. Most developers running auto-update are fine. Those on managed corporate machines, or who had not opened Telegram recently, are still exposed. This is exactly the same pattern seen with the GitHub Copilot CLI credential leak earlier this week — silent fixes leave the risk window open for users.
Conditions and Realistic Risk
The attack is not fully automatic. The victim must run a version before 7.2.9, be in a supergroup where the attacker pre-planted three instruction files (auto-downloaded by Telegram by default), and click a link outside the app — in a browser or email client — while Telegram Desktop is running. Links clicked within Telegram take a different IPC path and are not affected.
That said, the CybersecurityNews PoC coverage confirms exploitation code is now public. The attack conditions are common defaults. Developers frequently click documentation, CI notification, and repository links in browsers while Telegram runs in the background. Windows is the confirmed platform; macOS and Linux have the same tg:// mechanism, though the full chain has not been independently verified on those platforms. If you manage machines for a team, assume exposure until updated.
What You Need to Do Now
Check your version: Telegram Desktop → hamburger menu → About. If it shows anything before 7.2.9, update immediately from the official Telegram Desktop download page.
After updating, enable a local passcode: Settings → Privacy and Security → Local Passcode. This changes the session key derivation to use your chosen secret instead of the stored plaintext salt. If your tdata files are ever stolen, they become useless to the attacker. This setting exists and most users — including developers who should know better — have never touched it.
NixOS users: nixpkgs PR #572081 has merged with the 7.2.9 update. Other Linux distributions may lag behind; verify your package version or install directly from the official binary. The broader pattern is worth internalizing: a session key stored on disk with attacker-recoverable encryption is functionally a stored plaintext credential. Any local file read — by this CVE or a future one — becomes an account takeover. Enable the passcode. It is a 30-second fix that converts “game over” into “inconvenience.” For context on how widespread the desktop CVE problem has been this week, see also the LMCache CVSS 9.8 still awaiting patch.













