CYBER DELTA FORCESearch

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12.

CDF News DeskThe Hacker News14 Sept 2026, 11:28 pm
Image courtesy of The Hacker News. Original report
CDF REPORT

A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser.

What to watch next

Watch for revised fixed-version guidance and confirmation that mitigations are holding in affected environments.

What remains unknown

The available reporting does not establish whether the issue is being actively exploited in the wild.

The available reporting does not establish who is behind the activity, if an attacker is involved.

MORE IN DATA BREACHES

More cybersecurity reporting

240,000 Hit by Data Breach at Japan’s Digital AgencySecurityWeek · 15 Sept 2026, 5:15 pmPro-Ukraine Hacking Cat group deploying new malware against Russian targetsThe Record · 14 Sept 2026, 9:45 pmPersonal, Financial Info Exposed in Revolut Data BreachSecurityWeek · 14 Sept 2026, 6:33 pmWebinar: How malicious OAuth apps can lead to Google Workspace breachesBleepingComputer · 14 Sept 2026, 5:45 pm