CVE-2026-86185
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.
Açıklama ve Etki
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.
Referanslar
- https://app.bilibili.com/
- https://github.com/LeoWSY-hashblue/bilibili-desktop-tls-disabled-rce
- https://github.com/LeoWSY-hashblue/bilibili-desktop-tls-disabled-rce/blob/main/advisory.md
- https://www.vulncheck.com/advisories/bilibili-desktop-through-1.18.0-remote-code-execution-via-tls-verification-bypass
Güvenli Doğrulama Notu
Bu sayfa saldırı gerçekleştiren payload'lar çalıştırmaz. Doğrulama; etkilenen ürün/sürümün envanterden kontrol edilmesi, üretici güvenlik duyurusunun incelenmesi ve güncellemenin uygulanması üzerinden yapılmalıdır.