ZeroHour

CVE-2026-86185

mass

TLS Validation Bypass and Unsigned JavaScript Execution in Bilibili Desktop

CVSS 4.0
8.6 high
EPSS
<1%p1
Published
()
Modified
AI analysis

Bilibili Desktop through version 1.18.0 disables TLS certificate verification process-wide (CWE-295) and executes remotely fetched JavaScript configuration without signature or integrity checks. An attacker in an on-path network position — such as a hostile Wi-Fi access point, ISP, or corporate proxy — can intercept the client's configuration fetches and inject arbitrary JavaScript into the renderer. Because the injected code can reach the privileged IPC bridge, the attacker can execute system commands on the host or steal the user's login credentials. Anyone running the Bilibili Desktop client up to and including version 1.18.0 is affected, with the attack requiring adjacency to the victim's network traffic rather than an internet-reachable service. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS places 30-day exploitation probability at about 0.1%, so exploitation has not been observed.

What to do: Update Bilibili Desktop beyond 1.18.0 once the vendor publishes a fixed release, and confirm the changelog addresses certificate validation and configuration integrity. Until patched, avoid using the client on untrusted or shared networks (public Wi-Fi, shared LANs) or route it through a trusted VPN, since the attack requires an on-path position. Assume credentials entered in the client could be exposed if an on-path attacker was present, and monitor vendor channels for the advisory.

Affected
Bilibili Desktopall versions through 1.18.0 (≤ 1.18.0)
Estimated exposure
masslikely millions of desktop-client users (Bilibili's user base is in the hundreds of millions; the desktop client is a minority share, but platform scale… — No public install counts exist for the desktop client, so the estimate infers from Bilibili's scale as one of China's largest video platforms, assuming even a low single-digit percentage of its huge user base runs the desktop app.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.

Weakness
CWE-295
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.