securityaffairs.com 15 Sept 2026, 07:48 UTC

Telegram Desktop Flaw Let Attackers Steal Data from Chat Exports

Telegram Desktop Flaw Let Attackers Steal Data from Chat Exports
CyberSIXT Evidence Panel Source marked as original reporting

TELEGRAM Desktop contained a stored cross-site scripting (XSS) flaw in its HTML chat-export feature, according to researchers Denis and Aleksander Rostilov of ExPatch. A bot could create a message with a specially crafted inline keyboard and have it forwarded into other chats without joining them. When a user later exported a conversation containing that message and opened the HTML file in a browser, unescaped button text could be interpreted as JavaScript.

The researchers said the payload could read messages, sender names, timestamps and other metadata in the exported page, send the information to an attacker-controlled server, and access the export’s local file path. It could also alter the page, including replacing it with a fake Telegram verification screen. This was demonstrated as a potential attack; the article does not report confirmed exploitation.

The issue was traced to `export_output_html.cpp`, where inline-button text bypassed Telegram Desktop’s existing `SerializeString()` sanitisation routine. ExPatch rated it CVSS 8.2 (High), noting that exploitation required a user to export a chat and open the resulting file. The vulnerable code was introduced in February 2024 and reached stable release 4.15.1 in March 2024.

Telegram fixed the problem in June 2026 after a 3 June report, with the first fixed beta identified as 6.9.4 and the first fixed stable release as 7.0.1, released on 14 July 2026. No CVE had been assigned as of 11 September, according to the researchers.

Updating Telegram Desktop does not clean previously exported HTML files. Users and organisations should update to a current release, regenerate sensitive exports made with affected versions, and treat old Telegram HTML exports as untrusted rather than opening them in a normal browser.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline