CVE-2026-86185
massTLS Validation Bypass and Unsigned JavaScript Execution in Bilibili Desktop
Bilibili Desktop through version 1.18.0 disables TLS certificate verification process-wide (CWE-295) and executes remotely fetched JavaScript configuration without signature or integrity checks. An attacker in an on-path network position — such as a hostile Wi-Fi access point, ISP, or corporate proxy — can intercept the client's configuration fetches and inject arbitrary JavaScript into the renderer. Because the injected code can reach the privileged IPC bridge, the attacker can execute system commands on the host or steal the user's login credentials. Anyone running the Bilibili Desktop client up to and including version 1.18.0 is affected, with the attack requiring adjacency to the victim's network traffic rather than an internet-reachable service. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS places 30-day exploitation probability at about 0.1%, so exploitation has not been observed.
What to do: Update Bilibili Desktop beyond 1.18.0 once the vendor publishes a fixed release, and confirm the changelog addresses certificate validation and configuration integrity. Until patched, avoid using the client on untrusted or shared networks (public Wi-Fi, shared LANs) or route it through a trusted VPN, since the attack requires an on-path position. Assume credentials entered in the client could be exposed if an on-path attacker was present, and monitor vendor channels for the advisory.
| Bilibili Desktop | all versions through 1.18.0 (≤ 1.18.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.
- Weakness
- CWE-295
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.