Telegram Desktop Vulnerability Allows Hidden JavaScript to Exfiltrate Messages from HTML Exports
A vulnerability in Telegram Desktop allowed hidden JavaScript in HTML exports to exfiltrate messages from chats, with affected versions prior to July 2026 updates still posing risks for old exports. The flaw exploited unescaped inline keyboard buttons to execute scripts when opening exported files, requiring user updates to mitigate ongoing exposure.
A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12.
In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every message in that file to
*** END OF TRANSMISSION ***