Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

September 14, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: Medium
Victim: Telegram Desktop users
Incident: Cross-site scripting (XSS) vulnerability in the chat export feature.
Impact: Unauthorized exfiltration of chat messages and potential content spoofing within exported files.
Attacker: Malicious bot operators
Analysis: The vulnerability stems from improper sanitization of inline keyboard button text during the HTML export process. This allows a bot to embed hidden JavaScript that executes automatically when the exported file is opened in a web browser. While a patch is available, previously exported files remain a risk as they are not retroactively updated.
Recommendations: Update Telegram Desktop to the latest version immediately.; Avoid opening legacy HTML chat exports created prior to July 2024.; Exercise caution when exporting and storing sensitive chat histories as local HTML files.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *