FactaeThe Factual News

Telegram Desktop flaw enables message exfiltration via malicious HTML exports

A vulnerability in Telegram Desktop allows a bot to inject hidden JavaScript into HTML exports.

Published 2h1 sourceNotable
Lire en français
19s

The fact

The script runs when the user opens the exported file, exposing their messages.

ExPatch researchers published a detailed analysis on September 12, 2026.

Click the link to read an article on the topic:
Explore this topic
What if you saw the whole news differently?Factae cross-checks hundreds of sources worldwide to keep only the fact, no opinion. Explore the front page.
Follow topic →
Auto-synthesis from 1 media source · identified on September 14, 2026
Back to home
Discover

Read more

All cybersecurite →