2 min read

Telegram Desktop flaw leaves old chat exports exposed to data theft

Vlad CONSTANTINESCU

September 17, 2026

Telegram Desktop flaw leaves old chat exports exposed to data theft

A Telegram Desktop XSS flaw was patched in July, but HTML chat exports created with vulnerable versions can still contain executable code.

Key takeaways

  • Researchers found a stored XSS vulnerability in Telegram Desktop’s HTML chat-export function
  • Malicious JavaScript could remain dormant in a conversation until a user exported the chat and opened the HTML file in a browser
  • Telegram Desktop 7.0.1 was the first stable release containing the fix, but previously created HTML exports are not automatically repaired
  • ExPatch reported no known real-world exploitation and said no public CVE had been assigned as of its September disclosure

Old Telegram exports remain exposed

A recently disclosed Telegram Desktop vulnerability could turn previously exported chats into a data-theft trap, even after users update the messaging app.

Security researchers Denis Rostilov and Aleksander Rostilov of ExPatch found a stored cross-site scripting (XSS) flaw in Telegram Desktop’s HTML export feature. The issue affected exports created with stable versions before 7.0.1 and beta versions before 6.9.4. Telegram patched the bug in July 2026.

How the Telegram Desktop flaw worked

The vulnerability stemmed from the way Telegram Desktop handled text attached to bot inline-keyboard buttons. While other chat content was escaped before being written to HTML, button text could be inserted without the same sanitization. A malicious bot could therefore hide JavaScript in a message button. If that message was forwarded into another chat, the payload could remain in the conversation history without executing inside Telegram. The risk appeared later, when a participant exported the chat as HTML using a vulnerable desktop version and opened the file in a browser.

According to ExPatch, the injected script could read messages, sender names, timestamps and other data rendered in the affected HTML document and send it to an attacker-controlled server. It could also rewrite what the browser displayed, including replacing the export with a fake verification page. The original Telegram conversation itself would not be modified. The researchers rated the flaw 8.2 on the CVSS 3.1 scale. As of their Sept. 12 disclosure, no public CVE had been assigned, and their report identified no real-world exploitation.

What Telegram users should do now

Telegram Desktop 7.0.1, released July 14, was the first stable GitHub release containing the fix. However, updating the application does not sanitize HTML exports that were already created with vulnerable versions.

Users who saved Telegram conversations as HTML before updating should treat those files cautiously. ExPatch recommends recreating important exports with a patched version of Telegram Desktop or opening older files only with JavaScript disabled. Users should also avoid opening old exports from uncertain sources in a normal browser.

Add another layer of protection

For broader defense against malicious websites, phishing and scams delivered through chats and other channels, Bitdefender Ultimate Security combines multiplatform device security with scam-protection features. Bitdefender Scamio can also analyze suspicious messages, links and other potentially fraudulent content. These tools complement, rather than replace, the most important fix here: updating Telegram and recreating vulnerable HTML exports.

tags


Author


Vlad CONSTANTINESCU

Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.

View all posts

You might also like

Bookmarks


loader