Threat Intelligence

Telegram Desktop Bug Let Hidden Code Steal Messages From Exported Chat Files

The Hacker News · 15 Sept 2026
Key Takeaway If your business uses Telegram for communication, update Telegram Desktop now and treat any previously exported HTML chat files as potentially unsafe until re-exported with the latest version.

Security researchers at ExPatch have detailed a flaw in Telegram Desktop, the app's Windows, macOS, and Linux client, that could let a malicious bot hide JavaScript inside an ordinary-looking chat message. The trick relied on Telegram's inline keyboard buttons, which bots use to add clickable links under their messages. Before the fix, the export feature wrote button text straight into HTML files without properly escaping special characters, allowing hidden, invisible code to be smuggled in.

The danger appeared only when someone opened an exported HTML file of their chats in a web browser. At that point, the hidden script would run automatically, no clicking required, and could copy every message in the file, including sender names, timestamps, and even the local file path, to a server controlled by the attacker. Because the bot's message only needed to contain a web link button to survive forwarding, it could spread into group chats without the bot ever joining them, sitting quietly in chat history until someone exported it, potentially months or years later.

Telegram fixed the underlying issue in July after researchers reported it in June, but the fix only applies to new exports. Older HTML export files created before the patch may still contain the vulnerable code and pose a risk if opened. The researchers say they only tested the flaw in their own accounts and test groups, and found no evidence it was exploited against real users.

Telegram vulnerability data exfiltration messaging security JavaScript exploit

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.