Telegram Desktop flaw lets poisoned messages steal chat histories

A stored XSS vulnerability in Telegram Desktop allowed malicious bot messages to steal entire chat histories through exported HTML files.

By Central
Highlights
  • A flaw in Telegram Desktop's HTML export feature injected JavaScript via inline keyboard button text.
  • The attack required multiple user actions, including exporting chat history and opening the file in a browser.
  • Updating to Telegram Desktop 7.0.1 and recreating all previous HTML exports is the recommended fix.

A flaw in Telegram Desktop allowed specially crafted bot messages to inject JavaScript into HTML chat exports, creating a stored cross-site scripting (XSS) vulnerability that could expose the full contents of exported conversations, including messages, sender names, timestamps, and metadata. Discovered in June 2026 by security researchers Denis Rostilov and Aleksander Rostilov of ExPatch Vulnerability Research, the issue stemmed from incomplete sanitization of inline keyboard button text during the HTML export process. While Telegram patched the vulnerability in July 2026, any HTML exports created with older, vulnerable versions of Telegram Desktop may still contain dormant malicious code, and simply updating the application does not automatically repair those files.

How the Telegram Desktop XSS Vulnerability Worked

The vulnerability resided in Telegram Desktop’s HTML export feature, which allows users to save chat histories as HTML files for offline viewing in a web browser. When generating these files, the application properly escaped ordinary message content and other fields—such as user names and timestamps—before writing them into the document. However, the text displayed inside inline keyboard buttons was inserted directly without any sanitization. Inline buttons are interactive elements that bots can attach to messages; they appear as clickable buttons within the chat interface.

An attacker could create a bot message containing a hidden scriptcodecodecodecode element inside a button’s text field. Because Telegram Desktop itself does not interpret button text as HTML, the message would appear normal inside the application. The malicious content would only become active when a user exported the conversation using a vulnerable version of Telegram Desktop and then opened the resulting HTML file in a browser. At that point, the browser would execute the injected JavaScript, which could read any content displayed on the exported page.

The attack did not require the bot to be a member of the targeted group or have permission to read its messages. The attacker could send the prepared message to any chat and then have another user forward it into the target conversation. Telegram preserves certain inline buttons when messages are forwarded, enabling the malicious payload to remain dormant in the chat history until an export was triggered.

Exploitation Requires Multiple User Actions

The researchers emphasized that the vulnerability was not remotely exploitable in real time. For the attack to succeed, three conditions had to be met: the victim must have been using a vulnerable version of Telegram Desktop (pre-7.0.1), the malicious message must have been included in the chat history that the victim exported, and the victim must have opened the resulting HTML file in a web browser. Under those circumstances, the embedded JavaScript could execute and access all information displayed on the page, including exported messages, sender names, timestamps, and chat metadata. The researchers also demonstrated that the script could alter the document’s appearance, potentially replacing the exported conversation with a phishing page or modifying how the chat history was presented.

This makes the flaw a high-impact stored XSS vulnerability, but not one that can compromise users merely by receiving or viewing a Telegram message. The attack chain is similar to a “poisoned archive” scenario, where the danger lies in the exported file rather than in the live application.

Timeline of Discovery and Fix

The researchers discovered the issue on June 1, 2026, while examining Telegram Desktop’s HTML export functionality. They reported it to Telegram two days later, on June 3, along with proof-of-concept demonstrations. Telegram fixed the vulnerable code in commit 8457d13a by applying the same HTML sanitization routines already used elsewhere in the export process. According to the researchers, the fix first appeared in Telegram Desktop Beta 6.9.4 on July 3, 2026, and in the stable version 7.0.1 on July 14, 2026. No CVE had been assigned as of September 11, and Telegram had not published a dedicated security advisory.

Why Previously Exported Files Remain Dangerous

A critical nuance of this vulnerability is that updating Telegram Desktop to version 7.0.1 or later does not retroactively sanitize HTML files that were created with an older, vulnerable version. Those files continue to contain any malicious JavaScript that was injected into inline button text. If a user opens one of these old export files in a browser, the JavaScript will still execute. Therefore, security-conscious users who have exported Telegram chats using a pre-July 2026 version of Telegram Desktop should delete those files and recreate them after updating. This is the only way to guarantee that the exported HTML does not contain dormant malicious code.

What Is Stored Cross-Site Scripting (XSS) and Why It Matters

Stored XSS, also known as persistent XSS, occurs when an attacker injects malicious script into a web application that is then permanently stored and served to other users. In this case, the script is stored in the exported HTML file rather than in Telegram’s servers. While the attack vector is narrower than typical server-side stored XSS, the potential impact is significant for anyone who uses the HTML export feature to archive sensitive conversations. Chat exports may contain confidential business discussions, personal communications, or authentication codes. An attacker who could trick a target into exporting a conversation and then opening the file could exfiltrate that data.

Historical Context: Previous Telegram Desktop Vulnerabilities

Telegram Desktop has been the subject of several security advisories over the years. In 2023, researchers disclosed a vulnerability in the same HTML export feature that allowed arbitrary file reads through “file://” protocol injections. That flaw was also fixed without a public advisory. The recurrence of issues in the export feature suggests that the feature’s complexity and the different contexts in which user-supplied text is rendered make it a persistent attack surface. Telegram’s approach to security disclosures—often fixing issues in beta versions without formal advisories—has drawn criticism from some researchers who argue that users should be more transparently informed about the risks of exported files.

Practical Guidance for Telegram Desktop Users

Users should immediately verify their Telegram Desktop version. On Windows, navigate to Settings > About Telegram; on macOS, check Telegram > About Telegram. The current patched version is 7.0.1 or later. If your version is older, update it through the official Telegram website or your operating system’s package manager.

After updating, the next step is to locate any HTML chat exports created before July 14, 2026. These files are typically stored in a user-designated or default Downloads folder. Delete them. Then initiate a fresh export from the updated Telegram Desktop application. This ensures that the new HTML file is generated with proper sanitization of all inline button text.

For organizations that rely on Telegram Desktop for business communications, a broader review of archival practices may be warranted. If HTML exports are used as a record of official communications, consider whether alternative formats (such as JSON or plain text) might reduce the risk of XSS. Additionally, IT departments should ensure that users are aware that opening exported HTML files in a browser carries inherent risk, and that files from untrusted sources should never be opened.

Why the Vulnerability Was Hard to Detect

The flaw existed because of a mismatch in how Telegram Desktop handled inline button text in the live interface versus the export process. In the live application, button text is rendered using Telegram’s own UI framework, which does not interpret HTML. Developers naturally did not see a need to sanitize button text for client-side display. But when that same text was written into an HTML file, it was placed inside a <body>codecodecodecode element without any escaping. The sanitization that was applied to ordinary message content and other fields was simply not extended to this one data point. This type of “context mismatch” is a classic source of XSS vulnerabilities, especially when data moves from a safe rendering environment (Telegram’s chat window) to an unsafe one (a raw HTML file opened in a browser).

Broader Implications for Messaging Platform Security

The Telegram Desktop flaw highlights a blind spot in the security of messaging applications: the export feature. Most security research focuses on the live communication layer—encryption, authentication, message tampering, and account takeover. But the ability to export chat histories for backup, migration, or archiving introduces a new set of risks. If the export format is HTML, the application must ensure that all user-generated content is properly escaped for that context. Similarly, if the export format is PDF, the application must prevent injection into PDF rendering engines. The same principle applies to any feature that transforms internal data into a document that will be interpreted by another application.

Telegram’s fix was straightforward: apply the same HTML sanitization function that was already used for other fields to the inline button text. However, the fact that this sanitization was missing suggests that the export code had not undergone the same level of security review as the core messaging logic. Developers may have assumed that because button text could not contain rich formatting in the chat UI, it could not contain dangerous content in the export. This assumption turned out to be incorrect.

What This Means for Developers Building Export Features

For software engineers building similar features, the Telegram Desktop case offers a clear lesson: any code that inserts user-controlled data into a structured output format (HTML, XML, JSON, CSV, PDF) must apply output encoding appropriate for that format. The encoding must be context-aware: data placed inside HTML attribute values needs different encoding than data placed inside HTML element content. In this case, the button text was placed inside an HTML element (<button>codecodecodecode or similar), but the output was not entity-encoded. Developers should never rely on the fact that data was safe in one context to assume it is safe in another.

How to Identify Whether You Are Affected

If you have ever used Telegram Desktop to export a chat history as an HTML file, you may be affected if you were using a version prior to 7.0.1. To check which version you used at the time of export, you would need to recall the date of export and cross-reference it with the version history. Telegram Desktop does not embed version metadata in exported HTML files, so there is no automated way to determine if a given file was created with a vulnerable version. The safest course of action is to treat all HTML exports created before July 14, 2026, as potentially compromised. Delete them and recreate them with the updated application.

The Importance of Timely Updates and Re-Exports

Telegram fixed the vulnerability in the client, but that fix does not propagate to files already on disk. This is a fundamental distinction: patching the software protects future exports, but past exports remain vulnerable. Users who update Telegram Desktop but keep old export files are still exposed if they ever open those files. This situation is analogous to a document vulnerability in a word processor—the application is patched, but old documents created with vulnerable code may still contain exploits.

Given that Telegram did not issue a public security advisory, many users may be unaware that they need to take this additional step. The lack of an advisory is concerning because it places the burden of knowledge on security news outlets and the researchers themselves. Users who do not follow cybersecurity news may never learn that their exported chat files are potentially dangerous. This underscores the importance of transparent disclosure practices for vulnerabilities that affect user data even after the patch is applied.

What Telegram Could Have Done Differently

In addition to fixing the code, Telegram could have mitigated the risk by forcing a re-export of all previously exported chat files when the application is updated. This would have been technically challenging, as the application does not track which files were exported. A more feasible approach would have been to display an in-app notification after updating, warning users about the risk and advising them to delete and recreate old exports. Alternatively, Telegram could have added a version stamp to exported HTML files, allowing the application to later detect if a file was generated by a vulnerable version and warn the user when opening it. None of these measures were implemented.

The researchers also noted that Telegram had not published a dedicated security advisory as of September 11, 2026. This continues a pattern of under-communication around security updates. While Telegram has a bug bounty program, the program does not require public disclosure. Some security experts argue that for vulnerabilities that affect user data stored outside the application, a public advisory is necessary to ensure that all users are informed of the risk.

Technical Details of the Fix

The fix, contained in commit 8457d13a, added the same HTML sanitization routine that was already applied to message text when generating HTML exports. In the vulnerable version, the code that handled inline button text looked something like:

html += <button> + button.text + </button>codecodecodecode

The sanitized version applies an HTML encoding function (e.g., htmlEscape(button.text)codecodecodecode) before concatenation. This ensures that characters like <codecodecodecode, >codecodecodecode, &codecodecodecode, and "codecodecodecode are converted to their HTML entity equivalents, preventing the browser from interpreting them as markup. The same function was already used when writing message content to the export, so the fix was a one-line change in the relevant code path.

Impact on Telegram Desktop Users Worldwide

Telegram is one of the world’s largest messaging services, with hundreds of millions of monthly active users. The desktop client is widely used by journalists, activists, businesspeople, and ordinary consumers who often rely on it for sensitive communications. The HTML export feature is commonly used for creating records of conversations, transferring chat history to a different device, or backing up messages. While the vulnerability required multiple user actions to exploit, the potential for data exposure is serious, especially for users in high-risk environments such as human rights defenders, journalists, or corporate whistleblowers who may archive chat histories as part of their work.

It is also worth noting that the vulnerability could be combined with social engineering. An attacker could send a harmless-looking message containing a hidden script button to a user and then, through a separate channel (e.g., email), encourage the user to export their entire chat history for a seemingly legitimate reason. If the user complied and opened the exported file, the attacker could steal the entire conversation.

Comparisons with Similar Vulnerabilities in Other Messaging Apps

Web-based messaging platforms like Slack, Discord, and WhatsApp Web have also experienced XSS vulnerabilities in export or rendering features. Slack, for example, fixed a stored XSS in its export feature in 2021. WhatsApp Web had a vulnerability in 2020 that allowed HTML injection through contact names. The common thread is that any time user-generated text is pushed into a rich output like HTML, the risk of injection exists. Telegram Desktop’s vulnerability follows this pattern, but the specific mechanism of using forwarded bot messages with hidden inline buttons is novel.

Final Recommendation for All Telegram Desktop Users

Update to Telegram Desktop 7.0.1 or later immediately. After updating, delete all HTML chat exports created before the date of your update. Perform a fresh export of any conversations you wish to keep. Do not open old export files in a browser, even if you think they are clean. The presence of a dormant payload cannot be detected without examining the raw HTML source code for each file. For the vast majority of users, the safest and simplest action is to recreate the exports. This small step eliminates any lingering risk from this vulnerability and ensures that your archived Telegram conversations remain private.

Share This Article