Why it can be dangerous to keep Mini Apps open in Telegram or anywhere else: Focus Hijacking in practice

General News

Summary

This article explains how Telegram Mini Apps can be abused through focus hijacking techniques. It shows JavaScript patterns that repeatedly force window focus after blur events and uses timing behavior to study the parent app state. It also demonstrates how keydown-based logic can capture or manipulate user input, including clipboard actions. The piece frames this as a practical security risk for Mini Apps and similar web apps embedded inside messaging platforms.

Classifications

industries
No industries detected
applications
Collaboration & Communication

AskAI Classifications

Labels
Messaging Software Developer Tools API Management

Linked Companies

Telegram Messenger
$1M to $5M