When you boil it down, these are both just moderately complex stored XSS attacks, right? Construct a weird video or image, get it stored on the Telegram/WhatsApp servers, and if the user is using the web interface, they could trigger the malicious code by clicking on the image or opening the video in a new tab.