Remote Code Execution in Bilibili Desktop by Disabling TLS Certificate Verification
CVE-2026-86185

8.6HIGH

Key Information:

Vendor

Bilibili

Vendor
CVE Published:
5 September 2026

What is CVE-2026-86185?

Bilibili Desktop versions through 1.18.0 disable the TLS certificate verification process and allow execution of unsigned remote JavaScript configurations without integrity checks. This lack of security measures makes it possible for an attacker in an on-path network position to intercept configuration requests. They can inject arbitrary JavaScript that executes within the renderer context and has access to the privileged IPC bridge. This vulnerability opens up avenues for executing system commands or stealing sensitive information like login credentials, significantly compromising user security.

Affected Version(s)

Bilibili Desktop Windows 0 <= 1.18.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LeoWSY-hashblue
.