Bilibili 桌面版(1.18.0 及更早版本)在全局范围内禁用了 TLS 证书验证,并且在没有完整性校验的情况下执行未签名的远程 JavaScript 配置。位于网络链路中的攻击者(on-path)可以拦截配置文件的获取过程,注入任意的 JavaScript 代码,这些代码将在渲染进程中执行,并能够访问具有特权的 IPC 桥接接口,从而执行系统命令或窃取登录凭据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Bilibili | Bilibili Desktop | ≤ 1.18.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Bilibili | Bilibili Desktop | 0 ~ 1.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet