Back to all news
Security

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

The Hacker News·September 14, 2026·1 min read
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said. The script ran when someone opened the export file in a web browser, copying every message in that file.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store