CVE-2026-86185
HIGH
NVD
CVSS Score
8
Severity
HIGH
Published
Sep 05, 2026
Vendor
unknown
Description
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.
References
- https://app.bilibili.com/
- https://github.com/LeoWSY-hashblue/bilibili-desktop-tls-disabled-rce
- https://github.com/LeoWSY-hashblue/bilibili-desktop-tls-disabled-rce/blob/main/advisory.md
- https://www.vulncheck.com/advisories/bilibili-desktop-through-1.18.0-remote-code-execution-via-tls-verification-bypass