Executive brief
A vulnerability in the Telegram Desktop application can cause the software to crash when a user interacts with a specific type of malicious link. While the vendor disputes the severity, claiming it only results in a one-time application crash without permanent consequences, it can still disrupt user operations. Users are advised to update to version 6.7.6 to resolve the stability issue.
Technical details
A null pointer dereference vulnerability exists in Telegram Desktop up to version 6.7.5 within the RequestButton function of the Telegram/SourceFiles/boxes/url_auth_box.cpp file. The flaw is triggered by manipulating the login_url argument within the Bot API component. An attacker can remotely initiate this attack, though it requires user interaction (clicking a link). Successful exploitation results in a Denial of Service (DoS) via an application crash. The vendor has disputed the security significance, characterizing it as a one-time crash with no further impact. The issue is addressed in version 6.7.6.
Affected products
- Telegram Telegram Desktop up to 6.7.5
Timeline
- 2026-05-03: disclosed: Initial public disclosure of the vulnerability.
- 2026-05-03: advisory: CVE-2026-7701 published.
- 2026-05-19: other: Vendor disputed the vulnerability, claiming it only causes a one-time crash.