Summary
A high-severity XSS vulnerability in Telegram Desktop's export feature allows attackers to steal chat histories and manipulate records using hidden JavaScript in bot buttons. The flaw remains active in previously generated HTML exports even after the application is updated.
Take Action:
Update Telegram Desktop to version 7.0.1 (Stable) or 6.9.4 (Beta) ASAP, since older versions can hide malicious code inside exported HTML chat archives. Then find and delete any HTML chat exports made before July 2026. If you must keep one for legal reasons, only open it on an isolated machine with JavaScript turned off, or simply re-export the chat with the updated app.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)