A patched vulnerability in Telegram Desktop means that newly created chat archives are secure, but older HTML exports made before the fix remain dangerous files that could hand over private conversations to attackers. Researchers at ExPatch uncovered a stored cross-site scripting (XSS) flaw that allowed malicious code to be embedded directly into routine chat backups, creating hidden data-theft mechanisms within seemingly innocent files.

The flaw, first detailed by Security Affairs, existed in how Telegram Desktop generated its HTML chat exports. An attacker could place a specially crafted message in a public channel or group. When any user exported that chat history, the malicious payload was automatically bundled into the HTML file.

The attack required a victim to then open the compromised export in a web browser, which would execute the hidden script. This could silently steal the chat's contents, alter displayed information, or attempt to divert the user to a malicious site. The threat is particularly insidious because the export process is often used for legitimate record-keeping, meaning users could be creating their own security vulnerabilities without realizing it.

The Persistent Threat in Old Files

The most pressing issue now is the legacy risk. Telegram addressed the vulnerability in updates for Windows (v5.8.3) and macOS (v9.6.1). However, these patches only protect future exports. The countless HTML files already created and stored on user devices, backup drives, or cloud services are not automatically cleaned or neutralized.

This creates a significant and ongoing danger. Archived chats for project records or personal memories, whether for business or personal use, now represent a latent threat. A single click on one of these old files by a user—or access by an attacker—could trigger the data theft.

Clear Actions for Users

The recommended response is straightforward. Users must update Telegram Desktop to the latest version immediately. More critically, they need to audit and securely delete any existing HTML chat exports. IT administrators and individuals should review backup folders and archives to identify and remove these files. The chats themselves can be safely re-exported from the now-patched application if an archive is still needed.

This incident illustrates a fundamental security lesson. Exporting data from a secure, encrypted application like Telegram moves it into a different environment where responsibility shifts entirely to the user. That static HTML file is no longer protected by the app's security controls and is only as safe as the device storing it and the browser opening it. Every exported file is a potential vulnerability that must be managed with care.


Telegram 桌面版一個已被修補的安全漏洞意味著,新建立的聊天記錄匯出檔案現在是安全的,但在此之前建立的舊有 HTML 匯出檔案仍然是危險檔案,可能將私人對話內容洩露給攻擊者。安全研究組織 ExPatch 發現了一個儲存型跨站腳本攻擊漏洞,該漏洞允許惡意代碼直接嵌入常規的聊天記錄備份中,在看似無害的檔案內建立了隱蔽的數據竊取機制。

這個漏洞首先由 Security Affairs 詳細報導,它存在於 Telegram 桌面版生成 HTML 聊天記錄匯出檔案的方式中。攻擊者可以在公開頻道或群組中放置一條特別構造的訊息。當任何用戶匯出該聊天記錄時,惡意負載會自動被打包進 HTML 檔案中。

該攻擊需要受害者隨後在瀏覽器中打開受感染的匯出檔案,從而執行隱藏的腳本。這可能靜默地竄取聊天內容、更改顯示的資訊,或嘗試將用戶重定向至惡意網站。此威脅尤其險惡,因為匯出過程通常用於合法的記錄保存,這意味著用戶可能在不知情的情況下為自己製造了安全漏洞。

舊檔案中的持續威脅

目前最迫切的問題是歷史遺留風險。Telegram 已在 Windows(v5.8.3)和 macOS(v9.6.1)版本的更新中修補了此漏洞。然而,這些修補程式僅能保護未來的匯出操作。已經建立並儲存在用戶裝置、備份驅動器或雲端服務上的無數 HTML 檔案並不會被自動清理或中和。

這造成了重大且持續的危險。無論用於商業或個人用途,項目記錄或個人回憶的存檔聊天現在代表了一個潛在的威脅。用戶點擊這些舊檔案中的任何一個——或者攻擊者訪問它們——都可能觸發數據竊取。

用戶應採取的明確措施

建議的應對措施很直接。用戶必須立即將 Telegram 桌面版更新至最新版本。更為關鍵的是,他們需要審計並安全刪除任何現有的 HTML 聊天記錄匯出檔案。IT 管理員和個人都應檢查備份資料夾和存檔,以識別並移除這些檔案。如果仍需要存檔,聊天記錄本身可以從現已修補的應用程式中安全地重新匯出。

此次事件闡明了一個基本的安全教訓。從像 Telegram 這樣安全、加密的應用程式中匯出數據,會將其轉移到一個責任完全轉移給用戶的不同環境。那個靜態的 HTML 檔案不再受應用程式的安全控制措施保護,其安全性僅取決於儲存它的裝置和打開它的瀏覽器。每個匯出的檔案都是一個必須謹慎管理的潛在漏洞。

新聞來源 / Original News Source