Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
- ID
- 24367
- Status
- summarized
- Published
- 15 Sep 2026, 1:58 AM
- Fetched
- 15 Sep 2026, 4:45 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/telegram-desktop-flaw-lets-hidden.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 15 Sep 2026, 4:48 AM
- Tags
- Audience
- developersvibe_coders
What happened
Researchers at ExPatch found that Telegram Desktop's HTML export feature failed to escape bot inline-keyboard button text, allowing a bot to inject hidden JavaScript via a script tag padded with invisible characters. When a user exported a chat containing the bot's message and opened the HTML file in a browser, the script auto-ran—no click needed—and could exfiltrate every message, sender name, timestamp, and chat metadata to an attacker server. Telegram fixed the export code in July, but HTML files exported before the update still carry the payload.
Why it matters
If you or your team archive Telegram group chats as HTML exports for compliance, record-keeping, or sharing, any export made before the July fix could silently leak the entire chat contents when opened in a browser. Re-export affected chats with the patched Telegram Desktop version and treat old HTML export files as untrusted—open them in a sandbox or not at all. The bug is also a concrete reminder that any field rendered into HTML—bot button text included—must be escaped, not just the obvious fields like message body.
Discussion angle
How a forwarded message with no visible content can weaponize a downstream export pipeline months later—and what this pattern implies for any tool that renders user-controlled fields into downloadable HTML.