⚠️Telegram Desktop had a flaw that could quietly expose exported chats
A vulnerability in Telegram Desktop allowed attackers to hide JavaScript inside bot-generated message buttons. The code stayed harmless inside Telegram but could execute when a victim exported the chat as HTML and opened the file in a browser.
The script could read messages contained in the exported file — including names, timestamps and chat details and send them to an attacker-controlled server. Researchers also demonstrated that the exported page could be replaced with a fake Telegram verification screen.
The flaw was fixed in Telegram Desktop 7.0.1 and 6.9.4 beta. The important catch: HTML exports created before the fix can still contain the malicious code, even if Telegram is updated today.
🪙 TON News
🐳 Whale bot | 💰 Whale web
Post #576
397

- ❤ 1