Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Telegram Desktop Bug Exposed Chat Data

Critical Telegram Desktop Bug Exposed Chat Data

Posted on September 15, 2026 By CWS

A critical vulnerability in Telegram Desktop has been identified, allowing attackers to embed malicious JavaScript within bot-generated inline keyboard buttons. This flaw posed a risk to user data when chat histories were exported as HTML files.

Security Flaw and Resolution

The vulnerability was addressed in Telegram Desktop Beta 6.9.4 and Stable 7.0.1. However, HTML exports created with earlier versions may still be at risk. Security experts Denis and Aleksander Rostilov from ExPatch discovered the issue, which originated from the way text in inline keyboard buttons was processed in exported HTML files.

Telegram Desktop facilitates the export of individual chat threads or entire account histories into HTML documents for purposes such as archiving and compliance. Prior to the patch, these exports incorporated button text without adequate character escaping, enabling attackers to embed harmful HTML scripts.

Mechanics of the Exploit

The exploitation required several conditions: the presence of a malicious message in the chat history, use of a vulnerable Telegram Desktop version for export, and opening the exported HTML file in a browser with JavaScript enabled. Upon opening, the script could access and extract sensitive chat information such as messages, sender details, and timestamps.

Attackers could also manipulate visible content or redirect users to phishing sites by modifying the export page’s appearance. The flaw enabled attackers to implant dormant payloads in group chats, activating only when the HTML file was exported and opened, posing risks to compliance and legal processes.

Recommendations and Future Steps

Telegram has implemented a fix in commit 8457d13a, ensuring proper HTML escaping for inline button text. The fix is available from Telegram Desktop Beta 6.9.4 and Stable 7.0.1 onwards. Users are urged to upgrade to these versions or later to mitigate risks.

Organizations should audit and replace previous HTML exports from vulnerable versions, as these remain susceptible to exploitation. Treat legacy Telegram HTML files as potentially harmful, opening them only with JavaScript disabled, or regenerate them using a secure version.

This incident underscores the importance of regular software updates and vigilant cybersecurity practices to protect sensitive communications from evolving threats.

Cyber Security News Tags:bot message, chat security, cross-site scripting, Cybersecurity, data breach, desktop vulnerability, HTML export, JavaScript attack, Phishing, security patch, software update, technology news, Telegram

Post navigation

Previous Post: Vercel’s $1M Bug Bounty Reveals Linux Kernel Issues
Next Post: Iranian Spyware Targets Journalists Via Telegram

Related Posts

MediaTek July 2025 Security Update Patches Vulnerabilities Affecting a Wide Range of Their Chipsets MediaTek July 2025 Security Update Patches Vulnerabilities Affecting a Wide Range of Their Chipsets Cyber Security News
North Korea-Linked Hackers Target Developers via JavaScript North Korea-Linked Hackers Target Developers via JavaScript Cyber Security News
Interlock Ransomware Exploits Windows Tools for Credential Theft Interlock Ransomware Exploits Windows Tools for Credential Theft Cyber Security News
Aeternum Botnet’s Blockchain Strategy Challenges Security Aeternum Botnet’s Blockchain Strategy Challenges Security Cyber Security News
AmnesiaStealer Threatens Mac Security with Hidden Browser Control AmnesiaStealer Threatens Mac Security with Hidden Browser Control Cyber Security News
AI Enhances Security with Realistic Attack Simulations AI Enhances Security with Realistic Attack Simulations Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple Releases Major Security Update Fixing 273 Vulnerabilities
  • CISA Details 17 Hacker Tactics Targeting Active Directory
  • Exein Raises $270M for AI Security Expansion
  • Iranian Spyware Targets Journalists Via Telegram
  • Critical Telegram Desktop Bug Exposed Chat Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple Releases Major Security Update Fixing 273 Vulnerabilities
  • CISA Details 17 Hacker Tactics Targeting Active Directory
  • Exein Raises $270M for AI Security Expansion
  • Iranian Spyware Targets Journalists Via Telegram
  • Critical Telegram Desktop Bug Exposed Chat Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark