Find notable cyber news and cases, enriched with sources, timelines, and signals.

Telegram Desktop HTML export escaping fix

Security Patch Release
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

Telegram Desktop shipped a fix for an HTML export escaping flaw that could let a bot message inject JavaScript into exported chats. The update closed the issue for 6.9.4 beta and 7.0.1 stable, while older HTML exports created before the fix can still carry the script. Opening one of those files in a browser could expose chat content or let the page be rewritten.

Related Happenings

Telegram Desktop old HTML export mitigation

Advisory/Mitigation
H score30 First: 14.09.2026 20:58 Last: 14.09.2026 20:58 Sources 1

How related: Update Telegram Desktop to 7.0.1 or later, or to 6.9.4 or later on the beta channel.

About this happening: Telegram Desktop users with old HTML exports should update to 7.0.1 or 6.9.4 beta so pre-fix files no longer remain a browser-executed JavaScript risk. The res...

Trojanized Pyrogram forks with hidden Telegram backdoor

Malware Activity
H score14 First: 01.07.2026 00:02 Last: 01.07.2026 00:02 Sources 1

About this happening: Trojanized Pyrogram forks on PyPI now ship a hidden backdoor that gives attackers remote command execution and file access on compromised Telegram bot servers. The mal...

Timeline

  1. 14.09.2026 20:58 1 articles · 3h ago

    Researchers report Telegram Desktop HTML export JavaScript injection flaw

    Initial Disclosure

    ExPatch researchers Denis Rostilov and Aleksander Rostilov reported that a bot message in Telegram Desktop could plant hidden JavaScript inside HTML chat exports when inline keyboard button text was written without escaping.

    Show sources
  2. 14.09.2026 20:58 2 articles · 3h ago

    Telegram Desktop 7.0.1 ships HTML export escaping fix

    Mitigation Patch Update

    Telegram Desktop 7.0.1 stable added the missing escaping for inline keyboard button text in HTML exports, closing the path that let a bot message embed script in exported chats.

    Show sources
  3. 12.09.2026 03:00 1 articles · 2d ago

    ExPatch publishes Telegram Desktop HTML export exploit analysis

    Technical Analysis Update

    ExPatch published a writeup showing that a hidden script in a Telegram Desktop HTML export could run in a browser, copy messages and metadata to an attacker-controlled server, or rewrite the exported page.

    Show sources