ZeroHour

CVE-2026-75357

large

Unauthenticated Code Injection RCE in Bilibili Desktop 1.17.9

CVSS 3.1
9.8 critical
EPSS
<1%p48
Published
()
Modified
AI analysis

Bilibili Desktop version 1.17.9 contains a code injection vulnerability (CWE-94) in its bili-inject.js and bili-bridge.js components that allows a remote attacker to execute arbitrary code. Per the CVSS 3.1 scoring (AV:N/AC:L/PR:N/UI:N), the issue is exploitable over a network with no privileges or user interaction required. A successful attack grants arbitrary code execution with high impact on confidentiality, integrity, and availability on the affected system. Anyone running Bilibili Desktop 1.17.9 is affected, though the CVE data documents only that specific version and provides no fixed release. As of now there is no public proof of concept, no CISA KEV listing, and no confirmed exploitation in the wild, with EPSS estimating only a 0.6% probability of exploitation in the next 30 days.

What to do: Check the installed Bilibili Desktop version and upgrade to the latest vendor release as soon as a patched build is published, since no fixed version is documented yet. Until then, treat the desktop client as vulnerable and consider restricting its use to trusted content while monitoring for vendor advisories or the emergence of public exploit code. Given the low EPSS score and absence of a known PoC, there is no indication of active targeting at this time.

Affected
Bilibili Desktop1.17.9 (the only version documented; other versions may be affected but are not specified)
Estimated exposure
largelikely on the order of hundreds of thousands of desktop installs (estimate) — Bilibili's platform serves hundreds of millions of users in China, and desktop clients of large video platforms typically account for a small fraction of that base, suggesting an install base plausibly in the 100k-1M range; no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.

Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.