hacker-news · Crawled Sep 14, 2026

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

Read original article ↗

AI Summary

A vulnerability in Telegram Desktop versions 4.15.1 through 6.9.3 allowed malicious bots to embed hidden JavaScript within inline keyboard buttons, which could be executed when users opened HTML chat exports in a browser. The script could exfiltrate all messages in the exported file or rewrite the page content, such as displaying a fake verification form. The flaw was fixed in versions 6.9.4 (beta) and 7.0.1 (stable) released in July 2026, but previously exported HTML files remain vulnerable if opened in browsers with JavaScript enabled. No CVE has been assigned, and Telegram did not publicly acknowledge the issue despite confirmation and a declined bug bounty.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.