CyberRota Analysis
AI-GeneratedBilibili Desktop versions up to 1.18.0 are vulnerable due to the disabling of TLS certificate verification, allowing attackers in an on-path position to intercept configuration fetches and inject malicious JavaScript. This exploitation can lead to unauthorized execution of system commands and theft of sensitive information, such as login credentials. Organizations using this application should prioritize remediation to mitigate the risk of potential data breaches and system compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.