A Critical Flaw in Telegram Desktop Exposes Users’ Private Messages
A recently discovered vulnerability in the popular messaging app Telegram Desktop has left users vulnerable to a sophisticated attack that can exfiltrate their private messages. The flaw, which affects version 2.9 of the desktop client, allows an attacker to inject malicious JavaScript code into the app’s HTML exports, essentially turning the user’s own device against them.
The vulnerability works by exploiting a weakness in Telegram Desktop’s handling of cross-domain requests. In essence, when a user exports their chat history as an HTML file, the app creates a temporary web server on their local machine that allows external scripts to access and manipulate the exported data. An attacker can take advantage of this temporary server by sending a specially crafted request to the user’s device, which injects malicious JavaScript code into the exported HTML. This code can then extract sensitive information from the user’s messages, including conversation logs, file attachments, and even login credentials.
The affected users are those who have the Telegram Desktop app installed on their computers and have exported their chat history as an HTML file in the past six months. The flaw does not affect the mobile apps or web versions of Telegram. According to a security researcher who discovered the vulnerability, the attack requires no user interaction beyond opening the exported HTML file.
The implications of this vulnerability are significant, particularly for users who rely on Telegram as their primary means of secure communication. With the ability to extract sensitive information from private messages, an attacker can gain valuable insights into an individual’s personal life, including relationships, financial dealings, and potentially even business operations. This type of information can be used for targeted phishing attacks or even sold on the black market.
The good news is that Telegram has already issued a patch for the vulnerability, which users can download from their official website. Until then, users are advised to avoid exporting their chat history as an HTML file and instead use other methods, such as saving individual messages or photos directly from the app. Furthermore, users should remain vigilant about suspicious activity on their devices and report any unusual behavior to Telegram’s support team.
In light of this vulnerability, it is essential for users to take a closer look at their cybersecurity practices and ensure that they are not inadvertently exposing themselves to similar threats. By being aware of the potential risks associated with cross-domain requests and taking proactive measures to secure their data, users can significantly reduce the likelihood of falling victim to such attacks in the future.
Source: The Hacker News — 2026-09-14