PT-2026-86410 · Bilibili · Bilibili Desktop

·

CVE-2026-86185

·

Published

2026-09-05

·

Updated

2026-09-05

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bilibili Desktop versions prior to 1.18.0
Description The software disables TLS certificate verification across the entire process and executes unsigned remote JavaScript configurations without performing integrity checks. An attacker positioned on the network path can intercept configuration requests to inject arbitrary JavaScript. This code is executed in the renderer with access to the privileged IPC (Inter-Process Communication) bridge, which allows for the execution of system commands or the theft of login credentials.
Recommendations Update Bilibili Desktop to a version later than 1.18.0.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86185

Affected Products

Bilibili Desktop