A vulnerability in Telegram Desktop allowed a bot to inject hidden JavaScript into chats exported as HTML files, according to a security researcher's report published on September 12 This article explores vulnerability telegram desktop. . Telegram Desktop, the app for Windows, macOS, and Linux, allows users to save individual chats or all chats from an account as HTML pages that open in a browser.
The researchers, Denis and Aleksander Rostilov, discovered that the export code did not escape button text, sender names, or other fields, leading to potential security vulnerabilities. Researchers revealed that the script could access and read every message in the file, including sender names, timestamps, chat names, types, member counts, and the local file path, and transmit all this information to the attacker's server.
Three conditions were necessary for the script to execute: the HTML export was created with a Telegram Desktop version prior to the fix, the message containing the script was within the exported chat, and the file was opened in a browser with JavaScript enabled. They requested a coordinated publication date and agreed to remain silent until the patch was shipped. For example, if information about a vulnerability is made public, malicious actors may exploit it, leading to financial harm to Telegram users," Telegram Support stated in an email dated July 1, which included a screenshot of the researchers' work.












