Threat Advisory

Telegram Desktop Flaw Lets Bots Embed Hidden JavaScript in Chats

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A flaw in Telegram Desktop with a CVSS score of 8.2 allows a bot's message to plant hidden JavaScript inside chats that users exported to HTML files. The script runs only when someone opens the export file in a web browser, copying every message in that file to an attacker-controlled server or rewriting what the page displays. This vulnerability affects versions of Telegram Desktop from 4.15.1 through 6.9.3 and was fixed in version 7.0.1. A bot can attach rows of buttons under its messages without escaping them, allowing a script tag to be placed in a button's text. The bot does not need to be in the chat it targets as forwarded messages keep their buttons and can carry the script with them. When an export file containing the message was opened, the script ran without any further click, reading every message in that file and sending them all to the attacker's server. Three conditions must be met for the script to run: the HTML export was made using a Telegram Desktop. The business impact of this vulnerability is significant as it allows an attacker to access sensitive information such as sender names, timestamps, and local file paths.

RECOMMENDATION:

We recommend you to update Telegram Desktop to version 7.0.1 or later, or to 6.9.4 or later on the beta channel.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A flaw in Telegram Desktop with a CVSS score of 8.2 allows a bot's message to plant hidden JavaScript inside chats that users exported to HTML files. The script runs only when someone opens the export file in a web browser, copying every message in that file to an attacker-controlled server or rewriting what the page displays. This vulnerability affects versions of Telegram Desktop from 4.15.1 through 6.9.3 and was fixed in version 7.0.1. A bot can attach rows of buttons under its messages without escaping them, allowing a script tag to be placed in a button's text. The bot does not need to be in the chat it targets as forwarded messages keep their buttons and can carry the script with them. When an export file containing the message was opened, the script ran without any further click, reading every message in that file and sending them all to the attacker's server. Three conditions must be met for the script to run: the HTML export was made using a Telegram Desktop. The business impact of this vulnerability is significant as it allows an attacker to access sensitive information such as sender names, timestamps, and local file paths.

RECOMMENDATION:

We recommend you to update Telegram Desktop to version 7.0.1 or later, or to 6.9.4 or later on the beta channel.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu