😏 Telegram export with a catch
Researchers found a Telegram Desktop flaw that can hide malicious code inside an exported chat. When the HTML file is opened in a browser, the code can read the messages in that export and send them to an attacker-controlled server.
It can also collect names and timestamps or replace the page with a fake Telegram verification form.
↖️ https://durovscode.com/telegram-desktop-html-export-security-flaw
Post #4644
917

- 👍 15