CyberSecurity News
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
AI summary
A vulnerability in Telegram Desktop allowed a bot to embed hidden JavaScript in chat messages that were exported to HTML files. The malicious message appeared normal in the Telegram application, complete with a link button. However, when the HTML export file was opened in a web browser, the embedded script would execute. This script was capable of copying all messages contained in the exported HTML file. The issue was discovered by security researchers at ExPatch, who published their findings in a writeup. The script's execution was dependent on the user opening the exported file in a browser, at which point it could exfiltrate the messages.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

