PT-2026-86410 · Bilibili · Bilibili Desktop
CVSS v3.1
8.0
High
| Vector | AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bilibili Desktop versions prior to 1.18.0
Description
The software disables TLS certificate verification across the entire process and executes unsigned remote JavaScript configurations without performing integrity checks. An attacker positioned on the network path can intercept configuration requests to inject arbitrary JavaScript. This code is executed in the renderer with access to the privileged IPC (Inter-Process Communication) bridge, which allows for the execution of system commands or the theft of login credentials.
Recommendations
Update Bilibili Desktop to a version later than 1.18.0.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bilibili Desktop