Telegram asked us to stay silent about XSS. We are publishing anyway

Security researchers have discovered a critical XSS vulnerability in Telegram's HTML chat export feature. The flaw allowed attackers to compromise the privacy of correspondence via a specially crafted empty message. Although Telegram was notified of the issue, the company refused to coordinate a public disclosure and did not take steps to fix previously generated export files. The authors detail the technical causes of the vulnerability, share correspondence with the vendor, and explain why updating the app does not protect users who have already exported their data. Experts emphasize that old HTML exports remain dangerous as they contain malicious code that can be triggered when viewed in a browser. This case raises important questions about vendor transparency regarding security and responsibility for vulnerabilities in local user files.
This is a summary. Read the full article at the original source:
HabrRelated stories
Researchers demonstrate InjectEave: A technique to intercept audio through walls
Researchers from HKUST (Guangzhou) and HK PolyU have unveiled 'InjectEave,' a sophisticated eavesdropping technique capable of extracting audio from h…
The article discusses an innovative approach to digital content authentication, proposing the use of 'spymarks' as a superior alternative to tradition…
Cybersecurity researchers at Zimperium have identified a sophisticated new Android malware strain dubbed RatHat. Unlike traditional malware that relie…


