
A Telegram Desktop XSS flaw was patched in July, but HTML chat exports created with vulnerable versions can still contain executable code.
A recently disclosed Telegram Desktop vulnerability could turn previously exported chats into a data-theft trap, even after users update the messaging app.
Security researchers Denis Rostilov and Aleksander Rostilov of ExPatch found a stored cross-site scripting (XSS) flaw in Telegram Desktop’s HTML export feature. The issue affected exports created with stable versions before 7.0.1 and beta versions before 6.9.4. Telegram patched the bug in July 2026.
The vulnerability stemmed from the way Telegram Desktop handled text attached to bot inline-keyboard buttons. While other chat content was escaped before being written to HTML, button text could be inserted without the same sanitization. A malicious bot could therefore hide JavaScript in a message button. If that message was forwarded into another chat, the payload could remain in the conversation history without executing inside Telegram. The risk appeared later, when a participant exported the chat as HTML using a vulnerable desktop version and opened the file in a browser.
According to ExPatch, the injected script could read messages, sender names, timestamps and other data rendered in the affected HTML document and send it to an attacker-controlled server. It could also rewrite what the browser displayed, including replacing the export with a fake verification page. The original Telegram conversation itself would not be modified. The researchers rated the flaw 8.2 on the CVSS 3.1 scale. As of their Sept. 12 disclosure, no public CVE had been assigned, and their report identified no real-world exploitation.
Telegram Desktop 7.0.1, released July 14, was the first stable GitHub release containing the fix. However, updating the application does not sanitize HTML exports that were already created with vulnerable versions.
Users who saved Telegram conversations as HTML before updating should treat those files cautiously. ExPatch recommends recreating important exports with a patched version of Telegram Desktop or opening older files only with JavaScript disabled. Users should also avoid opening old exports from uncertain sources in a normal browser.
For broader defense against malicious websites, phishing and scams delivered through chats and other channels, Bitdefender Ultimate Security combines multiplatform device security with scam-protection features. Bitdefender Scamio can also analyze suspicious messages, links and other potentially fraudulent content. These tools complement, rather than replace, the most important fix here: updating Telegram and recreating vulnerable HTML exports.
tags
Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.
View all posts