Find notable cyber news and cases, enriched with sources, timelines, and signals.

Telegram Desktop HTML export script injection security flaw

Vulnerability
First reported
Last updated
Happening score
H score 25
1 unique sources, 1 articles

Summary

Hide ▲

Telegram Desktop's HTML export path let unescaped button text inject hidden JavaScript into saved chats, exposing pre-fix exports to message exfiltration or page rewriting when opened in a browser.

Related Happenings

Telegram Desktop old HTML export mitigation

Advisory/Mitigation
H score30 First: 14.09.2026 20:58 Last: 14.09.2026 20:58 Sources 1

How related: Update Telegram Desktop to 7.0.1 or later, or to 6.9.4 or later on the beta channel.

About this happening: Telegram Desktop users with old HTML exports should update to 7.0.1 or 6.9.4 beta so pre-fix files no longer remain a browser-executed JavaScript risk. The res...

XCSSET v40 macOS malware activity via compromised Xcode projects

Malware Activity
H score30 First: 04.08.2026 22:03 Last: 04.08.2026 22:03 Sources 1

About this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...

Trojanized Pyrogram forks with hidden Telegram backdoor

Malware Activity
H score14 First: 01.07.2026 00:02 Last: 01.07.2026 00:02 Sources 1

About this happening: Trojanized Pyrogram forks on PyPI now ship a hidden backdoor that gives attackers remote command execution and file access on compromised Telegram bot servers. The mal...

Operation Navy Ghost PyPI supply-chain campaign

Campaign
H score26 First: 01.07.2026 00:02 Last: 01.07.2026 00:02 Sources 1

About this happening: The Operation Navy Ghost campaign has targeted Python developers building Telegram bots through trojanized Pyrogram forks, creating a supply-chain path to compromi...

MacOS.Gaslight prompt-injection technique aimed at AI-assisted triage

Technical Analysis
H score23 First: 24.06.2026 17:00 Last: 24.06.2026 17:00 Sources 1

About this happening: macOS.Gaslight is a Rust-based macOS implant and information stealer assessed with high confidence as the work of North Korea-aligned threat actors. The sample uses ...

Timeline

  1. 12.09.2026 03:00 2 articles · 2d ago

    ExPatch publishes Telegram Desktop HTML export JavaScript injection writeup

    Untyped Phase

    ExPatch published a writeup showing that a bot message could plant hidden JavaScript in Telegram Desktop HTML exports and run when the exported file was opened in a browser. The demonstration showed message exfiltration and page rewriting in pre-fix exports.

    Show sources
  2. 14.07.2026 03:00 1 articles · 2mo ago

    Telegram Desktop 7.0.1 stable release ships the HTML export fix

    Mitigation Patch Update

    Telegram Desktop 7.0.1 became the first stable release with the HTML export escaping fix, replacing the unsafe write path in affected versions. Pre-fix HTML exports remained dangerous because updating the app does not rewrite older exported files.

    Show sources
  3. 03.07.2026 03:00 1 articles · 2mo ago

    Telegram Desktop 6.9.4 beta adds escaping for HTML export button text

    Mitigation Patch Update

    Telegram Desktop 6.9.4 beta introduced the escaping needed to stop untrusted inline-keyboard button text from becoming executable code in HTML exports. That change closed the JavaScript injection path for exports built from the fixed beta code.

    Show sources
  4. 01.07.2026 03:00 1 articles · 2mo ago

    Telegram confirms the Telegram Desktop export flaw and offers a bug bounty

    Untyped Phase

    Telegram confirmed the Telegram Desktop HTML export flaw after the researchers’ report and offered a $500 bug bounty. The response also set up the coordination around publication after a fix was available.

    Show sources
  5. 03.06.2026 03:00 1 articles · 3mo ago

    Researchers report Telegram Desktop HTML export JavaScript injection to Telegram

    Initial Disclosure

    Researchers told Telegram that Telegram Desktop HTML exports could carry hidden JavaScript when a bot’s inline-keyboard button text was written into HTML without escaping. A pre-fix export opened in a browser could let the script read chat contents or rewrite the rendered page.

    Show sources