← Terug naar overzicht

Bilibili Desktop through version 1.18.0 contains a critical vulnerability where TLS certificate verification is disabled process-wide, allowing on-path attackers to intercept network traffic. The application also executes unsigned remote JavaScript configuration files without integrity checks, compounding the risk. An attacker positioned on the network path can intercept configuration fetches and inject arbitrary JavaScript into the renderer process. The injected JavaScript has access to a privileged IPC bridge, enabling execution of system commands. Additionally, attackers can leverage this vulnerability to steal user login credentials. The attack requires an on-path network position (e.g., compromised Wi-Fi, ISP-level interception, or ARP spoofing). A proof-of-concept exploit and advisory have been published publicly on GitHub, increasing exploitation risk. The combination of TLS verification bypass and unsigned script execution represents a severe security design flaw.

Affected products

  • Bilibili Desktop 1.18.0

Related CVE's

  • CVE-2026-86185

Categories

  • Identity & Access
  • Web Technologies
  • Zero-Day Vulnerabilities