PT-2026-36705 · Telegram · Telegram Desktop
Oblivionsage
·
Published
2026-05-03
·
Updated
2026-05-03
·
CVE-2026-7701
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Telegram Desktop versions prior to 6.7.6
Description
A null pointer dereference (a condition where a program attempts to read from a memory address that is null, typically causing a crash) can be triggered remotely in the Bot API component. The issue exists within the
RequestButton() function located in the Telegram/SourceFiles/boxes/url auth box.cpp file, specifically through the manipulation of the login url argument.Recommendations
Update to a version newer than 6.7.5.
As a temporary workaround, restrict the use of the
RequestButton() function in the Bot API component.Fix
Improper Resource Release
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Telegram Desktop