Telegram Desktop old HTML export mitigation
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Telegram Desktop users with old HTML exports should update to 7.0.1 or 6.9.4 beta so pre-fix files no longer remain a browser-executed JavaScript risk. The researchers also advise reopening legacy exports only with JavaScript disabled or re-exporting the chats after updating. The guidance applies to exports created before the July fix, when older files could still carry the injected script.
Related Happenings
Telegram Desktop HTML export script injection security flaw
Vulnerability
H score25
First: 14.09.2026 20:58
Last: 14.09.2026 20:58
Sources 1
How related:
Until the fix, the export code wrote that button text directly into the HTML page without escaping it, the researchers Denis Rostilov and Aleksander Rostilov found.
About this happening:
Telegram Desktop's HTML export path let unescaped button text inject hidden JavaScript into saved chats, exposing pre-fix exports to message exfiltration or ...
Telegram Desktop HTML export script injection security flaw
VulnerabilityHow related: Until the fix, the export code wrote that button text directly into the HTML page without escaping it, the researchers Denis Rostilov and Aleksander Rostilov found.
About this happening: Telegram Desktop's HTML export path let unescaped button text inject hidden JavaScript into saved chats, exposing pre-fix exports to message exfiltration or ...
Telegram Desktop HTML export escaping fix
Security Patch Release
H score30
First: 14.09.2026 20:58
Last: 14.09.2026 20:58
Sources 1
How related:
The fix, commit 8457d13a by Telegram Desktop developer John Preston, adds the missing escaping.
About this happening:
Telegram Desktop shipped a fix for an HTML export escaping flaw that could let a bot message inject JavaScript into exported chats. The update closed the issue for 6...
Telegram Desktop HTML export escaping fix
Security Patch ReleaseHow related: The fix, commit 8457d13a by Telegram Desktop developer John Preston, adds the missing escaping.
About this happening: Telegram Desktop shipped a fix for an HTML export escaping flaw that could let a bot message inject JavaScript into exported chats. The update closed the issue for 6...
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware Activity
H score30
First: 04.08.2026 22:03
Last: 04.08.2026 22:03
Sources 1
About this happening:
XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
XCSSET v40 macOS malware activity via compromised Xcode projects
Malware ActivityAbout this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...
NodeBB eight-flaw security patch release (4.14.2)
Security Patch Release
H score34
First: 24.07.2026 10:41
Last: 24.07.2026 10:41
Sources 1
About this happening:
NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affect...
NodeBB eight-flaw security patch release (4.14.2)
Security Patch ReleaseAbout this happening: NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affect...
Timeline
-
14.09.2026 20:58 1 articles · 3h ago
Telegram Desktop 6.9.4 beta adds HTML export escaping for bot button text
Mitigation Patch UpdateTelegram Desktop 6.9.4 beta incorporated the missing escaping for inline keyboard button text in HTML exports, closing the path that let a bot message carry hidden JavaScript into exported chat pages.
Show sources
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58
-
14.09.2026 20:58 1 articles · 3h ago
Telegram Desktop 7.0.1 stable ships with the HTML export escaping fix
Mitigation Patch UpdateTelegram Desktop 7.0.1 brought the same HTML escaping fix to the stable channel, making the patched release available to users outside the beta track.
Show sources
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58
-
12.09.2026 03:00 2 articles · 2d ago
Researchers advise updating Telegram Desktop and re-exporting legacy HTML chats
Mitigation Patch UpdateResearchers advised updating Telegram Desktop to 7.0.1 or later, or 6.9.4 or later on the beta channel, then re-exporting any chats saved to HTML before the fix or opening old files only with JavaScript disabled because pre-fix exports can still carry the script.
Show sources
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58