chiprook
← Security
SecurityOctober 11, 2026, 10:02

Telegram Desktop HTML export stored XSS went unnoticed for 2.5 years

ExPatch researchers found a stored XSS in Telegram Desktop's HTML chat export: inline keyboard button text was not escaped. Telegram patched it in July 2026, but no CVE was assigned and the vulnerable code shipped in stable releases for about two years and four months.

Telegram Desktop HTML export stored XSS went unnoticed for 2.5 years
#Telegram
Read next
Security

Telegram Desktop 7.2.9 fixes CVE-2026-107181 account session theft

Security

Dayton Voted to Pause Flock Cameras; Two Went Back Online Anyway

Security

Pentagon breach of 3M records went undetected for nine months

Security

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks