Telegram Desktop fixed a flaw that let bot messages embed JavaScript in HTML exports to read or alter messages; old exports ...
A high-severity Telegram Desktop flaw allowed malicious JavaScript in bot-created buttons to steal chat content when conversations were exported as HTML.
A flaw in Telegram Desktop allowed specially crafted bot messages to execute JavaScript in HTML chat exports and expose ...