GHSA-fqf8-xgqj-hc63HighCVSS 8.0
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes...
🔗 CVE IDs covered (1)
📋 Description
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-86185
- https://app.bilibili.com
- https://github.com/LeoWSY-hashblue/bilibili-desktop-tls-disabled-rce
- https://github.com/LeoWSY-hashblue/bilibili-desktop-tls-disabled-rce/blob/main/advisory.md
- https://www.vulncheck.com/advisories/bilibili-desktop-through-1.18.0-remote-code-execution-via-tls-verification-bypass
- https://github.com/advisories/GHSA-fqf8-xgqj-hc63