CVE-2026-7701

MEDIUM

Telegram Desktop Bot API url_auth_box.cpp RequestButton null pointer dereference

Title source: cna
STIX 2.1

Description

A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. There is ongoing doubt regarding the real existence of this vulnerability. Upgrading to version 6.7.6 is able to resolve this issue. Upgrading the affected component is recommended. The vendor provides this rationale for the dispute: "[T]he described scenario does not lead to any security issue or vulnerability, and only causes a one-time crash. In the outlined scenario, the targeted user must perform an active action, which doesn't produce any consequences after the app is relaunched."

References (4)

Core 4
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-360870 | Telegram Desktop Bot API url_auth_box.cpp RequestButton null pointer dereference
https://vuldb.com/vuln/360870
Signature, Permissions Required signature permissions-required
VDB-360870 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/360870/cti
Third Party Advisory third-party-advisory
Submit #804341 | Telegram Telegram Desktop <= 6.7.5 NULL Pointer Dereference
https://vuldb.com/submit/804341
Media Coverage media-coverage
https://www.youtube.com/watch?v=xo9Bplsy1K8

Scores

CVSS v3 4.3
EPSS 0.0039
EPSS Percentile 31.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-404 CWE-476
Status published
Products (7)
Telegram/Desktop 6.7.0
Telegram/Desktop 6.7.1
Telegram/Desktop 6.7.2
Telegram/Desktop 6.7.3
Telegram/Desktop 6.7.4
Telegram/Desktop 6.7.5
Telegram/Desktop 6.7.6
Published May 03, 2026
Tracked Since May 03, 2026