[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fJDZOeo5M5OIRMJfzIycs07Ybp6OyVjx3i325ErffVaM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"85d0f673-567d-4317-ab91-d72cf5d67406","telegram-desktop-html-export-flaw-enables-javascript-based-message-exfiltration","8a28df5d-cb13-495f-87dd-db6217824bae","Telegram Desktop HTML Export Flaw Enables JavaScript-Based Message Exfiltration","A vulnerability in Telegram Desktop allowed attackers to embed malicious JavaScript within bot messages, which would execute silently when a victim opened an exported HTML chat file in a browser. This is a classic stored cross-site scripting (XSS) scenario, where the application failed to properly sanitize user-controlled content before rendering it as HTML. The danger is compounded by the fact that older exported files remain permanently vulnerable even after Telegram patched the flaw, meaning data exfiltration risk persists for any previously exported archives. This highlights how seemingly benign export features can become attack vectors when input sanitization is neglected. Users who routinely export chats for archival purposes may unknowingly carry forward exploitable files indefinitely.","**Immediate actions:**\n- Update Telegram Desktop to the latest patched version immediately to prevent generation of new vulnerable export files.\n- Audit and delete or quarantine any previously exported HTML chat files that may contain untrusted bot messages.\n- Avoid opening legacy HTML chat exports in a browser until they have been reviewed or regenerated with a patched version.\n\n**Long-term improvements:**\n- Establish a policy requiring all third-party communication tools to be evaluated for secure export\u002Fimport functionality before enterprise use.\n- Implement Content Security Policy (CSP) headers or sandboxed environments when viewing any externally generated HTML files.\n- Subscribe to vendor security advisories for all desktop communication applications to ensure timely awareness of newly disclosed vulnerabilities.\n\n**Detection measures:**\n- Monitor outbound network traffic from endpoints for unexpected data exfiltration events triggered by browser activity on local HTML files.\n- Deploy endpoint detection tools capable of flagging JavaScript execution originating from locally stored HTML export files.\n- Conduct periodic security awareness training to educate users on the risks of opening exported chat files from untrusted or bot-generated sources.",[12,13,14,15,16,17,18,19,20],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 7 – Continuous Vulnerability Management","CIS Control 9 – Email and Web Browser Protections","NIST SP 800-53 SI-3 (Malicious Code Protection)","NIST SP 800-53 SI-10 (Information Input Validation)","NIST SP 800-53 RA-5 (Vulnerability Monitoring and Scanning)","OWASP Top 10 A03:2021 – Injection (XSS)","NIST CSF DE.CM-4 (Malicious Code Detection)","GDPR Article 32 – Security of Processing (for organizations handling personal data via exported chats)","published","2026-09-14T20:22:04.714156+00:00","2026-09-14T20:22:04.392+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Ftelegram-desktop-flaw-lets-hidden.html","telegram-desktop-flaw-lets-hidden-javascript-exfiltrate-messages-from-html-expor-7b20c2","Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":36,"name":37,"slug":38,"description":39,"color":40},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":42,"name":43,"slug":44,"description":45,"color":46},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]