Telegram Bot Exfiltrates Messages via HTML Export Flaw

A flaw in Telegram Desktop allowed a bot's message to plant hidden JavaScript within chat exports. Security researchers at ExPatch discovered on September 12 that when users opened the exported HTML file, the script activated, copying all messages. The bot's message appeared ordinary, but facilitated data exfiltration.

Severity: High · Category: Data Exfiltration

Impact: Proprietary chat data exfiltrated from Telegram Desktop users.

Source: The Hacker News · Sep 14 2026 · Original source

What Happened

A flaw in Telegram Desktop allowed a bot's message to embed hidden JavaScript within chats that users exported to HTML files. While the message appeared ordinary in Telegram, often with a link button, the script would execute when the exported HTML file was opened in a web browser. This execution could then copy every message contained within that file to an attacker-controlled server, or it could rewrite the content displayed on the page. The bot did not need to be a member of the targeted chat; a message with web link buttons, when forwarded into a group, carried the script with it. This allowed the malicious message to reside in a chat's history and be exported months or years later. For the script to run, three conditions had to be met: the HTML export must have been created using a Telegram Desktop version released before the fix, the message containing the script had to be included within the exported chat, and the file needed to be opened in a web browser with JavaScript enabled.

Timeline

Technical Analysis

The underlying cause of the vulnerability was a lack of proper escaping in Telegram Desktop's HTML export code. When exporting chats to HTML files, the application wrote the text from inline keyboard buttons directly into the HTML page without converting special characters, such as '<', into their HTML entities. While other fields like message text and sender names were correctly escaped, button text was not. This omission allowed a bot to insert a `<script>` tag into a button's text. The researchers demonstrated that this script tag could be padded with invisible characters, making the button appear empty in the Telegram Desktop client. The vulnerability affected Telegram Desktop versions from 4.15.1 (March 2024) through 6.9.3. The fix, commit 8457d13a, addressed this by adding the necessary escaping to the button text during HTML export. The researchers focused their examination solely on Telegram Desktop's HTML export feature and did not investigate the JSON export format or export capabilities of other Telegram applications.

Impact

The hidden JavaScript, once executed, could read every message within the opened HTML export file. This included sensitive information such as sender names, timestamps, the chat's name, its type, the member count, and the local file path where the export was stored. This data could then be exfiltrated to an attacker-controlled server. Telegram Desktop's export mechanism splits large exports into multiple files, each containing up to 1,000 messages, meaning a single compromised file would expose at most its own contents, not the entire chat history or Telegram account. Beyond data exfiltration, the script also had the capability to rewrite the content displayed on the page. Researchers demonstrated this by replacing the entire export with a fake Telegram "verification" form. This control could also be used to alter dates, senders, or message text within a file being used as a record. The flaw did not, however, modify Telegram's own copy of the chat or the export file saved on disk. The researchers rated the flaw 8.2 out of 10 on the CVSS 3.1 scale. Importantly, HTML files exported using vulnerable versions of Telegram Desktop remain susceptible to this script even after the application itself has been updated.

Discovery & Response

The flaw was discovered by security researchers Denis Rostilov and Aleksander Rostilov at ExPatch on June 1, 2026. They reported it to Telegram two days later, on June 3, 2026. Telegram confirmed the flaw on July 1, 2026, and offered a $500 bug bounty, which the researchers declined, requesting it be given to charity instead. Telegram subsequently shipped a fix, with the corrected code appearing in version 6.9.4 beta on July 3, 2026, and the 7.0.1 stable release on July 14, 2026. These were the first fixed versions published on GitHub. Telegram Support communicated in a July 1 email that public disclosure of even addressed issues could put users at risk, which the researchers interpreted as a refusal to allow publication. Despite this, and stating that no non-disclosure agreement covered their report, the researchers published their writeup on September 12, 2026, after the fix had been released. As of September 14, Telegram's release notes for versions 6.9.4 and 7.0.1, the app's changelog, and their July 14 update announcement did not mention the fix. No security advisories were listed on the Telegram Desktop repository on GitHub, and no CVE identifier was assigned to the flaw. Telegram had not published any guidance for users holding older exports as of September 14. The researchers advised users to update Telegram Desktop to version 7.0.1 or later (or 6.9.4 or later on the beta channel), re-export any chats previously exported to HTML before the fix, or open old files only with JavaScript disabled. They also recommended treating any HTML export made before the fix as untrusted, particularly those from large groups where message origins are difficult to verify.

How Fencio prevents this

Sensitive data and an outbound channel ended up in the same context. The agent did not need to be malicious. It only needed to be convinced that sending the data somewhere was part of the job.

Fencio tracks sensitive data as it moves through an agent session and checks every outbound path, from links and images to emails and API calls. When classified data is about to leave, or a series of answers adds up to something the requester is not entitled to see, the response is blocked or redacted.

All incidents