A high-severity Telegram Desktop flaw allowed malicious JavaScript in bot-created buttons to steal chat content when conversations were exported as HTML.