Telegram Desktop HTML Export Flaw Allowed Stealthy JavaScript Injection into Chat History
Researchers from ExPatch have disclosed a vulnerability in the desktop version of Telegram that allowed stealthy injection of JavaScript into exported chat histories. The flaw enabled attackers to embed malicious scripts within HTML exports without altering the visible appearance of messages inside the messenger itself.
The root cause lay in how Telegram Desktop handled button captions placed by bots beneath messages. While the application properly escaped dangerous characters in message text, sender names, and other fields, it failed to sanitize the text labels on inline buttons. Attackers could hide scripts using invisible characters, and the button-based payload persisted even after messages were forwarded between chats.
Once a user performed an HTML export in a vulnerable version, the script would execute automatically upon opening the file in any browser with JavaScript enabled. The code could copy conversation contents to a remote server or replace the displayed history with fake content such as a phishing form mimicking Telegram verification. Because large exports are split into separate files of one thousand messages each, the entire account remained protected, but individual chat segments were exposed.
The vulnerability existed in versions ranging from 4.15.1 to 6.9.3. A fix was included in beta release 6.9.4 and the stable version 7.0.1 published on July 14. Importantly, the patch does not retroactively secure previously generated HTML files, prompting researchers to recommend re-exporting old chats after updating or viewing legacy exports with JavaScript disabled.
No confirmed cases of real-world exploitation have been reported. The attack required three simultaneous conditions: use of a vulnerable Telegram Desktop version for export, presence of a malicious bot message in the exported chat, and opening the resulting HTML file in a browser with active scripting.
Related articles
Top Cybersecurity Stories: SharePoint Exploits Warned by US Authorities, Citrix and WordPress Flaws Lead Weekly Rankings
Security NEXT has published its weekly ranking of the most viewed articles from September 27 to October 3, 2026, highlighting critical vulnerability disclosures and confirmed exploitation cases. US authorities issued warnings about active exploitation of five vulnerabilities affecting SharePoint and WordPress. Citrix NetScaler received multiple vulnerability advisories with two flaws already confirmed as exploited in the wild. Apple released iOS 26.7.1 to address vulnerabilities potentially used in targeted attacks against specific individuals. Other notable incidents include a personal data breach at Times Car car-sharing service and a ransomware attack impacting Keio Electric Railway operations.
Google Releases Chrome Update Fixing 11 Vulnerabilities Including Critical WebGL Flaw
Google has issued an update for its Chrome browser that addresses 11 security vulnerabilities across Windows, macOS, and Linux platforms. The release includes Chrome 154.0.8037.98 and 154.0.8037.97 for Windows and macOS, along with version 154.0.8037.97 for Linux. One vulnerability, CVE-2026-103628, received a Critical rating due to an out-of-bounds memory write in WebGL that was originally reported in August. Nine additional issues rated High severity affect components such as FileSystem, Compositing, Skia, FedCM, SVG, MediaStream, and WebRTC, including a buffer overflow tracked as CVE-2026-103631. The update also resolves a type confusion flaw in the V8 scripting engine and one Medium-severity issue. Google plans a gradual rollout over the coming days and weeks.
Browser Built on Mistakes: How Real-World Attacks Shaped Modern Browser Defenses
Browser security features such as process isolation, sandboxing, and restrictions on code execution were not designed in isolation but evolved directly in response to concrete attacks over more than a decade. Early threats like malicious Flash advertisements in 2015 demonstrated how a single compromised banner could compromise an entire system, prompting the industry to phase out plugins entirely. Later discoveries, including the Spectre vulnerability, forced browsers to implement stricter site isolation and timing-attack mitigations that remain in place today. Session hijacking and malicious browser extensions further drove the adoption of stronger cookie protections and permission models. BI.ZONE analysts trace this history through specific incidents to show why current architectures prioritize separation of sites into distinct processes. The resulting design reduces the blast radius of any single exploit and continues to adapt as new attack classes emerge.
cKEV Index Launches to Prioritize Vulnerabilities as AI Accelerates Exploit Development
CyberOK has introduced the open cKEV Index, a catalog of high-priority vulnerabilities ranked by the Urgent Patch Score (UPS) methodology. The index incorporates timelines of events such as exploit publication, proof-of-concept releases, and confirmed attacks to help organizations prioritize patching under resource constraints. It addresses the growing gap between rapid AI-assisted vulnerability discovery and slower remediation processes at both vendors and customers. Examples from Anthropic reports highlight how threat actors used AI agents for reconnaissance, code analysis, and exploit development against Android apps and web applications. Microsoft and Oracle have publicly linked increased vulnerability findings and larger patch releases to AI tooling. The UPS framework defines progressive phases from Radar to Emergency/IR, allowing teams to act on strong signals without waiting for full confirmation. An open version of the catalog is now available with detailed event histories for Urgent Patch and Emergency stages.