By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Telegram Desktop Flaw Exposes HTML Exported Messages

Security researchers at ExPatch disclosed on September 12 a critical vulnerability affecting Telegram Desktop that enabled the exfiltration of user messages from HTML exports. The flaw allowed a malicious bot's message to embed hidden JavaScript code within chats. When a user exported their Telegram conversations to an HTML file and subsequently opened this file in a web browser, the embedded script would automatically execute. This execution permitted the script to access and copy all messages contained within that specific HTML export file. The researchers detailed that the malicious message appeared innocuous to the user, presenting itself as a standard link button, thereby masking the underlying security threat. The exploit's effectiveness hinged on the user interacting with the exported HTML file, making it a targeted attack vector for users who regularly archive or share their chat histories. ExPatch's analysis highlighted that the vulnerability specifically impacted the Telegram Desktop application, suggesting that other Telegram clients might not be susceptible to this particular exploit. The researchers provided a detailed writeup of their findings, including technical specifications of the exploit and potential mitigation strategies, to inform users and the broader cybersecurity community. The disclosure serves as a reminder of the persistent risks associated with data export features and the importance of scrutinizing files, even those originating from trusted applications. While the exact number of affected users or the duration for which this vulnerability may have been exploitable remains unclear, the potential for sensitive message data to be compromised underscores the severity of the issue. Telegram has not yet issued a public statement or released a patch addressing this specific vulnerability, leaving users of the Desktop application potentially exposed until a fix is implemented. The exploit targets the trust users place in the integrity of exported data, demonstrating a sophisticated method of data theft that bypasses typical security measures by leveraging the functionality of web browsers themselves. This incident is likely to prompt further investigation into the security protocols of messaging applications and their data handling practices, particularly concerning user-exported content. The researchers' proactive disclosure aims to accelerate the development and deployment of a solution by Telegram to protect its user base from further data compromise.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.