buildOne report1 publisher Telegram patched a stored XSS in Telegram Desktop's HTML chat export in July, after the flaw shipped in stable releases for about 28 months. No CVE or advisory came with the fix, so teams that track exposure by CVE ID had nothing to match against.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives
- Insufficient
- Confidence50
buildOne report1 publisher Telegram Desktop 7.2.9 patches CVE-2026-107181, a CVSS 8.1 flaw where one clicked link in a group chat could steal a victim's logged-in account session. Every build up to 7.2.8 is vulnerable, so the fix helps a machine only once the patched client is installed.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence40
buildOne report1 publisher Telegram Desktop patched a flaw, rated CVSS 8.1, that let a single clicked link ship a user's whole account to an attacker's channel. The fix reached hundreds of millions of users in September, described in the changelog as a rendering improvement.
Reality
- Evidence58
- Adoption62
- Hype gap+8
- Incentives55
- Confidence58
ExPatch says Telegram Desktop wrote bot button text into HTML chat exports without escaping it from March 2024 until a July fix, and updating the app leaves every file the earlier builds wrote unchanged on disk.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence72
CloudSEK's BRIDGEHEAD report tracks forty npm typosquats whose install script tests for Windows underneath Linux, then pulls a Rust stealer that reads the host's wallets and cookies.
Publishers:cloudsek.com
Reality
- Evidence63
- Adoption27
- Hype gap+14
- Incentives74
- Confidence56