Telegram: Telegram Desktop Flaw Lets Attackers Steal Chat Messages Through Poisoned HTML Exports

Telegram: Telegram Desktop Flaw Lets Attackers Steal Chat Messages Through Poisoned HTML Exports

Telegram Desktop Vulnerability Exposed Chat Exports to XSS Attacks

A high-severity stored cross-site scripting (XSS) flaw in Telegram Desktop allowed attackers to embed malicious JavaScript in bot-generated inline keyboard buttons, compromising chat exports when opened as HTML files. The vulnerability, discovered by security researchers Denis and Aleksander Rostilov of ExPatch, affected how Telegram Desktop processed text in inline keyboard buttons during HTML exports.

The issue stemmed from improper escaping of special characters in button labels, enabling attackers to conceal malicious scripts including hidden Unicode characters to make buttons appear harmless. While Telegram’s desktop client displayed the content as plain text, exported HTML files rendered the payload as executable code when opened in a browser with JavaScript enabled.

Exploitation required multiple conditions: a malicious message in the chat history, export via a vulnerable Telegram Desktop version (pre-7.0.1), and opening the file in a JavaScript-enabled browser. Once triggered, the script could exfiltrate chat content including messages, sender details, timestamps, and metadata or manipulate the export page, such as displaying fake verification screens for phishing.

The flaw was particularly concerning due to its delayed attack potential. Malicious bot messages could be forwarded into private or public groups, remaining dormant until a user exported the chat. This posed risks for compliance, legal, or investigative workflows, as older exports might still contain active payloads.

Telegram patched the vulnerability in commit 8457d13a, released in Telegram Desktop Beta 6.9.4 (July 3, 2026) and Stable 7.0.1 (July 14, 2026). The vulnerable code had existed since version 4.15.1 (March 2024). While the fix prevents new exploits, older HTML exports remain unsafe unless regenerated with a patched version. The attack did not alter server-side messages but could manipulate browser-based exports.

Source: https://cybersecuritynews.com/telegram-desktop-flaw/

Telegram Messenger cybersecurity rating report: https://www.rankiteo.com/company/telegram-messenger

"id": "TEL1789467999",
"linkid": "telegram-messenger",
"type": "Vulnerability",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of Telegram Desktop '
                                              'versions 4.15.1 to 7.0.0',
                        'industry': 'Technology/Messaging',
                        'name': 'Telegram',
                        'type': 'Software Company'}],
 'attack_vector': 'Malicious bot-generated inline keyboard buttons in chat '
                  'exports',
 'customer_advisories': 'Users advised to update Telegram Desktop and '
                        'regenerate older HTML exports',
 'data_breach': {'data_exfiltration': 'Possible via malicious JavaScript '
                                      'payloads',
                 'file_types_exposed': 'HTML chat exports',
                 'personally_identifiable_information': 'Sender details, chat '
                                                        'metadata',
                 'sensitivity_of_data': 'Medium (personally identifiable '
                                        'information, chat history)',
                 'type_of_data_compromised': 'Chat messages, sender details, '
                                             'timestamps, metadata'},
 'date_resolved': '2026-07-14',
 'description': 'A high-severity stored cross-site scripting (XSS) flaw in '
                'Telegram Desktop allowed attackers to embed malicious '
                'JavaScript in bot-generated inline keyboard buttons, '
                'compromising chat exports when opened as HTML files. The '
                'vulnerability stemmed from improper escaping of special '
                'characters in button labels, enabling attackers to conceal '
                'malicious scripts including hidden Unicode characters. '
                'Exploitation required a malicious message in the chat '
                'history, export via a vulnerable Telegram Desktop version '
                '(pre-7.0.1), and opening the file in a JavaScript-enabled '
                'browser. The script could exfiltrate chat content or '
                'manipulate the export page for phishing.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'phishing risks and data exfiltration',
            'data_compromised': 'Chat content (messages, sender details, '
                                'timestamps, metadata)',
            'identity_theft_risk': 'Potential risk due to exfiltration of '
                                   'sender details and chat metadata',
            'operational_impact': 'Risk to compliance, legal, or investigative '
                                  'workflows due to delayed attack potential',
            'systems_affected': 'Telegram Desktop (versions 4.15.1 to 7.0.0)'},
 'investigation_status': 'Resolved',
 'lessons_learned': 'Importance of proper input sanitization in exported '
                    'files, delayed attack potential in stored XSS, and risks '
                    'to compliance workflows',
 'post_incident_analysis': {'corrective_actions': 'Fixed in commit 8457d13a, '
                                                  'released in versions 6.9.4 '
                                                  '(Beta) and 7.0.1 (Stable)',
                            'root_causes': 'Improper escaping of special '
                                           'characters in inline keyboard '
                                           'button labels during HTML exports'},
 'recommendations': 'Update to patched versions (7.0.1 or later), regenerate '
                    'older HTML exports, disable JavaScript in browsers when '
                    'opening untrusted HTML files, and educate users on '
                    'phishing risks from manipulated exports',
 'references': [{'source': 'ExPatch (Denis and Aleksander Rostilov)'}],
 'response': {'containment_measures': 'Patch released in Telegram Desktop Beta '
                                      '6.9.4 (July 3, 2026) and Stable 7.0.1 '
                                      '(July 14, 2026)',
              'recovery_measures': 'Users advised to regenerate older HTML '
                                   'exports with patched versions',
              'remediation_measures': 'Fixed improper escaping of special '
                                      'characters in commit 8457d13a'},
 'title': 'Telegram Desktop Vulnerability Exposed Chat Exports to XSS Attacks',
 'type': 'Stored Cross-Site Scripting (XSS)',
 'vulnerability_exploited': 'Improper escaping of special characters in button '
                            'labels during HTML exports'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.