Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Telegram Desktop Update Fixes Critical JavaScript Flaw

Telegram Desktop Update Fixes Critical JavaScript Flaw

Posted on September 14, 2026 By CWS

Security researchers from ExPatch have uncovered a significant vulnerability in Telegram Desktop, allowing malicious JavaScript to be embedded in chat exports saved as HTML files. This flaw, identified on September 12, allowed attackers to exfiltrate messages and modify exported chat data when opened in a web browser.

Vulnerability Details and Impact

The vulnerability was present in Telegram Desktop versions 4.15.1 through 6.9.3 on Windows, macOS, and Linux platforms. It allowed a bot to insert hidden JavaScript within a message’s inline button, which was then directly embedded into exported HTML files without proper character escaping. Upon opening these files in a browser, the script could transmit chat data to an unauthorized server or manipulate the content displayed.

Although Telegram released a fix in July, earlier exports remain vulnerable if they were created before the update. Consequently, users need to be cautious with older HTML exports, as they can still harbor malicious scripts.

Telegram’s Response and Fix Implementation

Telegram addressed the issue swiftly after being informed on June 3, with a fix implemented in Telegram Desktop version 7.0.1 on July 14, 2026. The fix, developed by John Preston, involves adding the necessary escaping for button text to prevent JavaScript execution. Despite the update, Telegram has not issued public advisories or a CVE identifier for this flaw.

Users are advised to update to the latest version of Telegram Desktop and re-export any chats previously saved as HTML. If using older exports, disabling JavaScript in the browser is recommended to prevent unauthorized script execution.

Recommendations for Users

The researchers suggest treating any HTML export made before the update as potentially untrustworthy, especially if originating from large group chats where message origins are unclear. As of September 14, no official guidance from Telegram has been provided for managing older exports.

Additionally, the researchers have declined a $500 bug bounty offered by Telegram, requesting it be donated to charity instead. Their publication of the vulnerability aimed to raise awareness without jeopardizing user security, given the lack of a non-disclosure agreement.

In summary, users are encouraged to ensure their Telegram Desktop application is updated to the latest version to safeguard against this vulnerability. By following these recommendations, users can protect their chat data from potential exploitation.

The Hacker News Tags:chat security, Cybersecurity, data exfiltration, desktop app, HTML export, JavaScript vulnerability, security flaw, software patch, software update, Telegram

Post navigation

Previous Post: UK Introduces Passkeys for 23 Million GOV.UK Users
Next Post: Critical Nintendo Switch Flaw Allows Code Execution

Related Posts

Preinstalled Apps on Ulefone, Krüger&Matz Phones Let Any App Reset Device, Steal PIN Preinstalled Apps on Ulefone, Krüger&Matz Phones Let Any App Reset Device, Steal PIN The Hacker News
Critical Adobe Acrobat Reader Flaw Patched Amid Exploitation Critical Adobe Acrobat Reader Flaw Patched Amid Exploitation The Hacker News
Drift Faces 5M Loss in Social Engineering Heist Drift Faces $285M Loss in Social Engineering Heist The Hacker News
Qilin Ransomware Combines Linux Payload With BYOVD Exploit in Hybrid Attack Qilin Ransomware Combines Linux Payload With BYOVD Exploit in Hybrid Attack The Hacker News
AI Threats and Security Vulnerabilities Highlighted This Week AI Threats and Security Vulnerabilities Highlighted This Week The Hacker News
Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft’s $30,000 Bounty for AI Vulnerabilities
  • Critical Nintendo Switch Flaw Allows Code Execution
  • Telegram Desktop Update Fixes Critical JavaScript Flaw
  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft’s $30,000 Bounty for AI Vulnerabilities
  • Critical Nintendo Switch Flaw Allows Code Execution
  • Telegram Desktop Update Fixes Critical JavaScript Flaw
  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark