Unauthorized Screen Capture in Jitsi Electron SDK Before Version 10.0.5
CVE-2026-92299
7.1HIGH
What is CVE-2026-92299?
The Jitsi Electron SDK before version 10.0.5 contains a critical vulnerability that allows attackers to access desktop sources without user consent. By exposing the getDesktopSources() method via contextBridge, any script present in the meeting page can enumerate screens and windows. Additionally, attackers can exploit the jitsi-screen-sharing-get-sources IPC route to retrieve desktop thumbnails in arbitrary resolutions, bypassing necessary user permissions and operating system alerts.
Affected Version(s)
@jitsi/electron-sdk 0 < 10.0.5
