Feeds.Feedburner Telegram Desktop XSS Vulnerability Exposes Exported Chat Histories
Article Content
- •Telegram Desktop's XSS flaw allows bots to embed malicious JavaScript in HTML exports.
- •The vulnerability affects versions before 6.9.4 (Beta) and 7.0.1 (Stable), with a fix released in July 2026.
- •Exported HTML files from vulnerable versions can still contain malicious scripts even after updating the app.
A stored cross-site scripting (XSS) vulnerability in Telegram Desktop allows malicious bots to embed hidden JavaScript in exported HTML chat files. This flaw enables the extraction of all messages and metadata from the exported file when opened in a browser. The issue arises from improper sanitization of inline keyboard button text during the HTML export process. The vulnerability affects Telegram Desktop versions prior to 6.9.4 (Beta) and 7.0.1 (Stable), with a fix released in July 2026. Security researchers Denis and Aleksander Rostilov discovered the flaw on June 1, 2026, and reported it on June 3. Although the vulnerability has been patched, previously exported HTML files remain at risk. As of September 14, 2026, no CVE has been assigned for this issue. The potential impact includes unauthorized access to sensitive information contained in chat histories.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track AWS and CVE-2022-30190 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…