텔레그램 데스크톱의 취약점이 HTML 파일 내 숨겨진 자바스크립트를 통해 메시지를 유출할 수 있다.
텔레그램 데스크톱에서 발견된 취약점은 사용자가 HTML 파일로 내보낸 채팅 안에 숨겨진 자바스크립트를 삽입할 수 있게 해준다. 이 스크립트는 사용자가 내보낸 파일을 웹 브라우저에서 열 때 실행되며, 파일 내 모든 메시지를 복사할 수 있다. 보안 연구자들은 이 문제에 대해 ExPatch에서 발표하였다.
A flaw in Telegram Desktop allows hidden JavaScript to exfiltrate messages from HTML exports.
A vulnerability in Telegram Desktop enables a bot to plant hidden JavaScript in chats that users export to HTML files. The message appears ordinary with a link button, and the script executes when the exported file is opened in a web browser, allowing it to copy all messages in that file. Security researchers reported this issue in a publication by ExPatch.