CVE-2026-86185 PUBLISHED

Bilibili Desktop through 1.18.0 Remote Code Execution via TLS Verification Bypass

Assigner: VulnCheck
Reserved: 05.09.2026 Published: 05.09.2026 Updated: 05.09.2026

Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor Bilibili
Product Bilibili Desktop
Versions Default: unaffected
  • affected from 0 to 1.18.0 (incl.)

Credits

  • LeoWSY-hashblue finder

References

Problem Types

  • Improper Certificate Validation CWE