Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
The Hacker News · Sep 14, 2026
A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every message in that file to
Read original on The Hacker News
Want to stay informed about new business solutions?
Follow us
Ready to build a better digital experience?
We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.