Telegram Desktop had a high-risk vulnerability (CVE-2026-107181) in versions 7.2.8 and earlier that could allow account takeover through command injection and session file theft. The flaw has been fixed in version 7.2.9 released September 17.