Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

A Critical Flaw in Telegram Desktop Exposes Messages to Hidden JavaScript Attacks

A newly discovered vulnerability in the Telegram desktop app has left millions of users vulnerable to a sophisticated hacking technique that can exfiltrate sensitive messages from exported HTML files. The flaw, which was disclosed by security researchers this week, allows malicious JavaScript code to be injected into seemingly innocuous exports of chat logs, making it possible for hackers to extract confidential information.

At the center of this vulnerability is Telegram’s desktop app, which has become a favorite among users seeking end-to-end encrypted messaging and file sharing. While its popularity stems from its robust security features, the recent discovery highlights that even the most secure platforms can have hidden weaknesses. The issue lies in the way Telegram handles HTML exports, which are used to share chat logs with others or archive conversations. These exports contain JavaScript code embedded within them, allowing users to view and interact with their messages.

The problem arises when a malicious actor injects additional JavaScript code into these exports, which can then be executed by the user’s browser or desktop app. This injected code can access sensitive information stored in the exported HTML file, including chat logs, files shared during conversations, and even authentication tokens used to verify users’ identities. The attacker’s ultimate goal is to extract this data without the user’s knowledge or consent.

The vulnerability affects all versions of the Telegram desktop app since 2015, making it a critical issue that requires immediate attention from the company’s developers. While the scope of the attack appears to be limited to users who export their chat logs as HTML files, the potential for abuse is significant. Hackers can use this technique to gain unauthorized access to sensitive information, compromise user accounts, or even spread malware by injecting malicious code into exported files.

The discovery highlights the importance of reviewing and updating software regularly, particularly when it comes to messaging apps that handle sensitive data. Users are advised to exercise caution when sharing chat logs or exporting conversations as HTML files, and developers should prioritize patching this vulnerability to prevent further exploitation. By staying vigilant and proactive in maintaining security, users can minimize their exposure to such threats and protect themselves from potential attacks.

In light of this discovery, it’s essential for users to be aware of the risks associated with sharing chat logs or exported conversations. When exporting HTML files, ensure that you only share them with trusted individuals, and verify the recipient’s identity before doing so. Moreover, regularly review your software updates and install the latest patches to prevent exploitation by malicious actors. By taking these precautions, you can significantly reduce the risk of falling victim to this type of attack.


Source: The Hacker News — 2026-09-14