#javascript


Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

Sep 15, 2026 // 19:50

A flaw in Telegram Desktop let a bot’s message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said […]

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

Sep 14, 2026 // 23:22

A flaw in Telegram Desktop let a bot’s message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said […]

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Aug 20, 2026 // 17:17

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that […]

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Aug 20, 2026 // 17:07

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that […]

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Aug 20, 2026 // 16:57

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that […]

Malicious sites use JavaScript to build malware in browser memory

Jul 25, 2026 // 18:36

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. The […]

Critical flaw in Protobuf library enables JavaScript code execution

Apr 18, 2026 // 18:17

Proof-of-concept exploit code has been published for a critical remote code execution flaw in protobuf.js, a widely used JavaScript implementation of Google’s Protocol Buffers. The […]

Wikipedia hit by self-spreading JavaScript worm that defaced pages.

Mar 6, 2026 // 00:09

On March 5, 2026, Wikipedia and its sister projects were placed in read-only mode for approximately two hours following a site-wide attack by a self-propagating JavaScript worm. The […]