Impact
An attacker can run arbitrary code within the Bilibili Desktop application by exploiting vulnerable scripts in the bili-inject.js and bili-bridge.js components. The flaw allows the execution of malicious code; based on the description, it is inferred that the vulnerability can be triggered without authentication or user interaction, potentially giving full control over the host system.
Affected Systems
The vulnerability affects Bilibili Desktop version 1.17.9. No other versions or products were disclosed. The components that process IPC messages are the primary points of compromise.
Risk and Exploitability
The CVSS score is 9.8. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to involve remote interaction with the Desktop application, possibly through crafted IPC messages. It is inferred that the attacker could trigger the vulnerability without user interaction, which would allow full compromise of the host system. Because arbitrary code execution can be achieved remotely, the risk to confidentiality, integrity, and availability is severe.
OpenCVE Enrichment