Telegram Desktop Flaw Could Exfiltrate Exported Chat Histories via Hidden XSS Code
A newly disclosed security flaw in Telegram Desktop allows malicious actors to embed harmful code in exported chat files, potentially giving them access to an entire conversation history when the file is opened.
The vulnerability is a stored cross‑site scripting (XSS) bug that targets the HTML format used for Telegram's chat export feature. By inserting a crafted payload into an inline keyboard button within the exported document, an attacker can trigger the script whenever the file is viewed in a web browser, enabling the theft of the full transcript.
Security researchers who examined the issue say the exploit works because the exported HTML does not adequately sanitize the data associated with inline keyboard elements. When a user clicks the malicious button, the embedded script runs with the same privileges as the viewer’s browser, allowing it to harvest the displayed text and transmit it to a remote server controlled by the attacker.
Telegram Desktop, the multi‑platform client used by millions worldwide, offers the export function as a convenient way to back up or share conversation records. The flaw therefore poses a risk not only to individual users who might unknowingly open a tampered export, but also to organizations that rely on Telegram for internal communications and may distribute exported logs for compliance or archival purposes.
The vulnerability was first reported by the independent security group GBHackers, who provided technical details to Telegram’s security team. As of the time of writing, Telegram has not issued a public statement or released a patch, though the company typically responds to such disclosures with updates to its software.
Experts advise users to exercise caution when handling exported chat files, especially those received from untrusted sources. Opening the HTML export in a sandboxed environment or converting it to a PDF using trusted tools can mitigate the risk. Meanwhile, the broader security community watches for a forthcoming fix, noting that prompt remediation is essential to preserve confidence in Telegram’s desktop client and its data‑export capabilities.
Comments (0)
Be the first to comment.
Join the discussion