Junglewise Threat Intelligence

CVE-2026-7701: Telegram Desktop null pointer dereference in Bot API

CVE-2026-7701 · Severity: medium · CVSS 4.3 · Published 2026-05-03

Executive brief

A vulnerability in the Telegram Desktop application can cause the software to crash when a user interacts with a specific type of malicious link. While the vendor disputes the severity, claiming it only results in a one-time application crash without permanent consequences, it can still disrupt user operations. Users are advised to update to version 6.7.6 to resolve the stability issue.

Technical details

A null pointer dereference vulnerability exists in Telegram Desktop up to version 6.7.5 within the RequestButton function of the Telegram/SourceFiles/boxes/url_auth_box.cpp file. The flaw is triggered by manipulating the login_url argument within the Bot API component. An attacker can remotely initiate this attack, though it requires user interaction (clicking a link). Successful exploitation results in a Denial of Service (DoS) via an application crash. The vendor has disputed the security significance, characterizing it as a one-time crash with no further impact. The issue is addressed in version 6.7.6.

Affected products

  • Telegram Telegram Desktop up to 6.7.5

Timeline

  • 2026-05-03: disclosed: Initial public disclosure of the vulnerability.
  • 2026-05-03: advisory: CVE-2026-7701 published.
  • 2026-05-19: other: Vendor disputed the vulnerability, claiming it only causes a one-time crash.

References

Related threats