The record
Written from the 1 report below. Nothing here is unsourced.
- A flaw in Telegram Desktop allowed a bot to hide JavaScript in exported HTML chat files through unescaped inline button labels, researchers at ExPatch reported on September 12.
- When a person opened such an export file in a browser, the script could send every message in the file, including sender names and timestamps, to an attacker's server without any further click.
- The bot did not need to be in the target chat, because any group member who forwarded the bot's link-button message carried the hidden script into the group's history.
- Telegram fixed the flaw in the 6.9.4 beta on July 3 and in the 7.0.1 stable release on July 14, but files exported with older versions remain vulnerable even after the app is updated.
- Telegram has published no user guidance, no CVE identifier, and no mention of the fix in its release notes, leaving holders of old HTML exports with no official warning.
What to watch next
- Whether Telegram publishes an advisory, CVE identifier, or guidance for users with older HTML exports.
- Whether the U.S. National Vulnerability Database assigns a severity score, which did not exist as of September 14.
- Whether researchers or Telegram address the JSON export format or export features of Telegram's other apps.
Who said what1
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Telegram Support
1 quote · 1 outlet
“We also have considered the possibility of a public disclosure, but we cannot approve it as disclosing even the already addressed issues could put more Telegram users at risk in the future. For instance, if information about a vulnerability is made public, malicious actors may attempt to exploit it, thereby causing financial harm to Telegram users”
In the article
…confirmed the flaw on July 1 and offered a $500 bug bounty, which they declined and asked to be given to charity. They asked for a coordinated publication date and offered to stay silent until the patch shipped. " We also have considered the possibility of a public disclosure, but we cannot approve it as disclosing even the already addressed issues could put more Telegram users at risk in the future. For instance, if information about a vulnerability is made public, malicious actors may attempt to exploit it, thereby causing financial harm to Telegram users ," Telegram Support wrote in an email dated July 1 that the researchers published as a screenshot. The researchers read that as a refusal to allow publication even after a fix. They say no non-disclosure agreement…
Coverage1
All filed from India
Named United States · Telegram Desktop · Aleksander Rostilov · Denis Rostilov · ExPatch · John Preston · Telegram
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
