AI Weekly Malaysia

Back to items Summaries

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

ID
24367
Status
summarized
Published
15 Sep 2026, 1:58 AM
Fetched
15 Sep 2026, 4:45 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/telegram-desktop-flaw-lets-hidden.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.5
Created
15 Sep 2026, 4:48 AM
Tags
Audience
developersvibe_coders

What happened

Researchers at ExPatch found that Telegram Desktop's HTML export feature failed to escape bot inline-keyboard button text, allowing a bot to inject hidden JavaScript via a script tag padded with invisible characters. When a user exported a chat containing the bot's message and opened the HTML file in a browser, the script auto-ran—no click needed—and could exfiltrate every message, sender name, timestamp, and chat metadata to an attacker server. Telegram fixed the export code in July, but HTML files exported before the update still carry the payload.

Why it matters

If you or your team archive Telegram group chats as HTML exports for compliance, record-keeping, or sharing, any export made before the July fix could silently leak the entire chat contents when opened in a browser. Re-export affected chats with the patched Telegram Desktop version and treat old HTML export files as untrusted—open them in a sandbox or not at all. The bug is also a concrete reminder that any field rendered into HTML—bot button text included—must be escaped, not just the obvious fields like message body.

Discussion angle

How a forwarded message with no visible content can weaponize a downstream export pipeline months later—and what this pattern implies for any tool that renders user-controlled fields into downloadable HTML.

Top