Skip to content
Telegram Desktop XSS Vulnerability Exposes Exported Chat Histories

Telegram Desktop XSS Vulnerability Exposes Exported Chat Histories

First seen 14 Sep 2026, 20:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 22:23 UTC
  • Telegram Desktop's XSS flaw allows bots to embed malicious JavaScript in HTML exports.
  • The vulnerability affects versions before 6.9.4 (Beta) and 7.0.1 (Stable), with a fix released in July 2026.
  • Exported HTML files from vulnerable versions can still contain malicious scripts even after updating the app.

A stored cross-site scripting (XSS) vulnerability in Telegram Desktop allows malicious bots to embed hidden JavaScript in exported HTML chat files. This flaw enables the extraction of all messages and metadata from the exported file when opened in a browser. The issue arises from improper sanitization of inline keyboard button text during the HTML export process. The vulnerability affects Telegram Desktop versions prior to 6.9.4 (Beta) and 7.0.1 (Stable), with a fix released in July 2026. Security researchers Denis and Aleksander Rostilov discovered the flaw on June 1, 2026, and reported it on June 3. Although the vulnerability has been patched, previously exported HTML files remain at risk. As of September 14, 2026, no CVE has been assigned for this issue. The potential impact includes unauthorized access to sensitive information contained in chat histories.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2022-03-02
Public exploit for CVE-2022-30190 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2022-11-01
CVE-2022-3656 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-01
Vulnerability discovered
Researchers found a flaw in Telegram Desktop's HTML export feature that allows JavaScript injection.
Cyberinsider
2026-06-03
Flaw reported to Telegram
The researchers reported the vulnerability to Telegram, providing proof-of-concept demonstrations.
Cyberinsider
2026-07-03
Fix released in Beta version
Telegram released a fix for the vulnerability in Beta version 6.9.4.
Cyberinsider
2026-07-14
Stable version fix released
The stable version 7.0.1 of Telegram Desktop included the fix for the vulnerability.
Cyberinsider
2026-09-12
Public disclosure of vulnerability
ExPatch published a writeup detailing the XSS vulnerability in Telegram Desktop.
Cyberinsider
2026-09-14
No CVE assigned
As of today, no CVE has been assigned for the vulnerability despite its public disclosure.
Expatch

More articles in this cluster (3)

Following this threat?

Track AWS and CVE-2022-30190 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed