Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

Executive Summary

Security researchers discovered that a flaw in Telegram Desktop allows a malicious bot to embed hidden JavaScript in chat messages. When users export chats to HTML and open the file in a browser, the script runs and copies all messages from the file, exfiltrating them to the attacker. The vulnerability was reported on September 12 by ExPatch.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-14T17:58:16+00:00 - Category: threat-intel

Original Description: A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every message in that file to

"A life spent making mistakes is not only more honourable but more useful than a life spent in doing nothing."

— Bernard Shaw
Source: The Hacker News