Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-86185— Bilibili Desktop through 1.18.0 Remote Code Execution via TLS Verification Bypass

Quick assessment

Affected
Bilibili Bilibili Desktop
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Bilibili 桌面版(1.18.0 及更早版本)在全局范围内禁用了 TLS 证书验证,并且在没有完整性校验的情况下执行未签名的远程 JavaScript 配置。位于网络链路中的攻击者(on-path)可以拦截配置文件的获取过程,注入任意的 JavaScript 代码,这些代码将在渲染进程中执行,并能够访问具有特权的 IPC 桥接接口,从而执行系统命令或窃取登录凭据。

CVSS 8.0 · High EPSS 0.11% · P1

Affected Version Matrix 1

VendorProduct Version RangeStatus
Bilibili Bilibili Desktop ≤ 1.18.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86185

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bilibili Desktop through 1.18.0 Remote Code Execution via TLS Verification Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Bilibili Bilibili Desktop 0 ~ 1.18.0 -

II. Public POCs for CVE-2026-86185

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86185

登录查看更多情报信息。

Vendor Advisories for CVE-2026-86185 (1)

Proof of Concept for CVE-2026-86185 (2)

Other References for CVE-2026-86185 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-86185

No comments yet


Leave a comment