Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

The Hacker News · Sep 14, 2026

Back to News
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
Security September 14, 2026

A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every message in that file to

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.