Telegram Desktop HTML export script injection security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Telegram Desktop's HTML export path let unescaped button text inject hidden JavaScript into saved chats, exposing pre-fix exports to message exfiltration or page rewriting when opened in a browser.
Related Happenings
Telegram Desktop old HTML export mitigation
Advisory/Mitigation
H score30
First: 14.09.2026 20:58
Last: 14.09.2026 20:58
Sources 1
How related:
Update Telegram Desktop to 7.0.1 or later, or to 6.9.4 or later on the beta channel.
About this happening:
Telegram Desktop users with old HTML exports should update to 7.0.1 or 6.9.4 beta so pre-fix files no longer remain a browser-executed JavaScript risk. The res...
Telegram Desktop old HTML export mitigation
Advisory/MitigationHow related: Update Telegram Desktop to 7.0.1 or later, or to 6.9.4 or later on the beta channel.
About this happening: Telegram Desktop users with old HTML exports should update to 7.0.1 or 6.9.4 beta so pre-fix files no longer remain a browser-executed JavaScript risk. The res...
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware Activity
H score30
First: 04.08.2026 22:03
Last: 04.08.2026 22:03
Sources 1
About this happening:
XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware ActivityAbout this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
Trojanized Pyrogram forks with hidden Telegram backdoor
Malware Activity
H score14
First: 01.07.2026 00:02
Last: 01.07.2026 00:02
Sources 1
About this happening:
Trojanized Pyrogram forks on PyPI now ship a hidden backdoor that gives attackers remote command execution and file access on compromised Telegram bot servers. The mal...
Trojanized Pyrogram forks with hidden Telegram backdoor
Malware ActivityAbout this happening: Trojanized Pyrogram forks on PyPI now ship a hidden backdoor that gives attackers remote command execution and file access on compromised Telegram bot servers. The mal...
Operation Navy Ghost PyPI supply-chain campaign
Campaign
H score26
First: 01.07.2026 00:02
Last: 01.07.2026 00:02
Sources 1
About this happening:
The Operation Navy Ghost campaign has targeted Python developers building Telegram bots through trojanized Pyrogram forks, creating a supply-chain path to compromi...
Operation Navy Ghost PyPI supply-chain campaign
CampaignAbout this happening: The Operation Navy Ghost campaign has targeted Python developers building Telegram bots through trojanized Pyrogram forks, creating a supply-chain path to compromi...
MacOS.Gaslight prompt-injection technique aimed at AI-assisted triage
Technical Analysis
H score23
First: 24.06.2026 17:00
Last: 24.06.2026 17:00
Sources 1
About this happening:
macOS.Gaslight is a Rust-based macOS implant and information stealer assessed with high confidence as the work of North Korea-aligned threat actors. The sample uses ...
MacOS.Gaslight prompt-injection technique aimed at AI-assisted triage
Technical AnalysisAbout this happening: macOS.Gaslight is a Rust-based macOS implant and information stealer assessed with high confidence as the work of North Korea-aligned threat actors. The sample uses ...
Timeline
-
12.09.2026 03:00 2 articles · 2d ago
ExPatch publishes Telegram Desktop HTML export JavaScript injection writeup
Untyped PhaseExPatch published a writeup showing that a bot message could plant hidden JavaScript in Telegram Desktop HTML exports and run when the exported file was opened in a browser. The demonstration showed message exfiltration and page rewriting in pre-fix exports.
Show sources
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58
-
14.07.2026 03:00 1 articles · 2mo ago
Telegram Desktop 7.0.1 stable release ships the HTML export fix
Mitigation Patch UpdateTelegram Desktop 7.0.1 became the first stable release with the HTML export escaping fix, replacing the unsafe write path in affected versions. Pre-fix HTML exports remained dangerous because updating the app does not rewrite older exported files.
Show sources
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58
-
03.07.2026 03:00 1 articles · 2mo ago
Telegram Desktop 6.9.4 beta adds escaping for HTML export button text
Mitigation Patch UpdateTelegram Desktop 6.9.4 beta introduced the escaping needed to stop untrusted inline-keyboard button text from becoming executable code in HTML exports. That change closed the JavaScript injection path for exports built from the fixed beta code.
Show sources
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58
-
01.07.2026 03:00 1 articles · 2mo ago
Telegram confirms the Telegram Desktop export flaw and offers a bug bounty
Untyped PhaseTelegram confirmed the Telegram Desktop HTML export flaw after the researchers’ report and offered a $500 bug bounty. The response also set up the coordination around publication after a fix was available.
Show sources
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58
-
03.06.2026 03:00 1 articles · 3mo ago
Researchers report Telegram Desktop HTML export JavaScript injection to Telegram
Initial DisclosureResearchers told Telegram that Telegram Desktop HTML exports could carry hidden JavaScript when a bot’s inline-keyboard button text was written into HTML without escaping. A pre-fix export opened in a browser could let the script read chat contents or rewrite the rendered page.
Show sources
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58