VRCX是VRCX团队的一个 VRChat 的助手/配套应用程序。 VRCX 2024.03.23之前版本存在安全漏洞,该漏洞源于具有超权限和通过覆盖通知进行跨站脚本的CefSharp浏览器可以组合使用,从而导致远程命令执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: XSS via unsanitized overlay notification image field led to RCE — /tmp/vrcx-rce-pwned created via CefSharp AppApiVr elevated binding
No comments yet