Remote Code Execution in Bilibili Desktop by Disabling TLS Certificate Verification
CVE-2026-86185
8.6HIGH
What is CVE-2026-86185?
Bilibili Desktop versions through 1.18.0 disable the TLS certificate verification process and allow execution of unsigned remote JavaScript configurations without integrity checks. This lack of security measures makes it possible for an attacker in an on-path network position to intercept configuration requests. They can inject arbitrary JavaScript that executes within the renderer context and has access to the privileged IPC bridge. This vulnerability opens up avenues for executing system commands or stealing sensitive information like login credentials, significantly compromising user security.
Affected Version(s)
Bilibili Desktop Windows 0 <= 1.18.0
