Telegram Desktop Flaw Lets Attackers Steal Chat Messages Through Poisoned HTML Exports

A high-severity Telegram Desktop vulnerability let attackers hide JavaScript in bot-created inline keyboard buttons and steal chat content when victims exported conversations as HTML files. Telegram fixed the issue in Desktop Beta 6.9.4 and Stable 7.0.1, but HTML exports created with older versions may remain unsafe. Security researchers Denis Rostilov and Aleksander Rostilov of ExPatch […]

This article has been indexed from Cyber Security News

Read the original article: