Telegram Desktop Bug Enables Silent JavaScript Injection via Exported Chats
A security flaw in the Telegram Desktop client allowed malicious JavaScript to be embedded in HTML chat exports, researchers from ExPatch reported on September 12. The vulnerability was triggered when a bot sent a seemingly innocuous message containing a link button; the message’s payload carried hidden script code that activated when the exported HTML file was opened in a browser.
Telegram’s desktop application offers users the ability to export conversation histories as HTML files for offline viewing or archival purposes. The export process normally renders messages as static text and media, but the discovered flaw let specially crafted messages inject executable JavaScript into the generated page. When a recipient opened the HTML file, the hidden script could run without any visible indication, potentially allowing data exfiltration or other unwanted actions.
The ExPatch team detailed the attack vector in a technical write‑up, noting that the malicious code could harvest the contents of the exported chat and transmit them to an attacker‑controlled server. Because the exploit relies on the client‑side rendering of the HTML export, it bypasses Telegram’s server‑side safeguards and operates entirely on the user’s device.
While the researchers did not disclose evidence of the flaw being used in the wild, the vulnerability raises concerns for users who frequently back up their conversations in HTML format. Security experts stress that opening exported files from untrusted sources should be treated with the same caution as any other potentially unsafe document. The issue also underscores the broader challenge of balancing convenience features, such as easy chat exports, with robust security controls.
Telegram has not issued an official comment or patch at the time of this reporting. The Hacker News, which originally broke the story, highlighted the need for the messaging platform to address the weakness promptly. In the meantime, ExPatch recommends that users avoid opening HTML exports from unknown contacts and consider alternative backup methods, such as encrypted JSON exports, until a fix is deployed.
Comments (0)
Be the first to comment.
Join the discussion