57
42
42
42
42
47
57
57
42
Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories
Stored XSS in Telegram Desktop HTML chat exports (CVSS 8.2) could let attacker-controlled inline keyboard buttons steal full chat histories.
ExPatch researchers Denis and Aleksander Rostilov found a stored XSS in Telegram Desktop's HTML chat export pipeline affecting builds before Beta 6.9.4 and Stable 7.0.1. Unsanitized inline keyboard button text becomes executable JavaScript when a user exports a chat and opens the HTML file in a browser, exposing messages, metadata, and local file paths, and enabling phishing overlays. Telegram patched the issue in commit 8457d13a during July 2026; no CVE had been assigned at disclosure time.
52
42
42
60
47
57
57
42
42
57
47
57
47
57
42
42
42
47
42
57
42
42
42
42
42
47
57
42
42
42
42