Impact
Bilibili Desktop versions up to 1.18.0 disable TLS certificate verification globally and execute unsigned remote JavaScript configuration scripts. This flaw allows an attacker who can intercept network traffic to inject arbitrary JavaScript into the renderer process. The injected code runs with full IPC bridge privileges, enabling system command execution or theft of user credentials. The weakness is a Certificate Validation Bypass (CWE‑295).
Affected Systems
The vulnerability affects Bilibili Desktop applications published under the Bilibili product line. All releases through version 1.18.0 are impacted; later releases may have re‑enabled TLS verification, but the exact version roll‑out is not specified here.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity, and while a current EPSS score is not provided, the lack of a KEV listing does not reduce the risk because an on‑path attacker can exploit the flaw by simply intercepting configuration requests. The likely attack vector involves a man‑in‑the‑middle position on the network, allowing the attacker to modify the configuration payload and inject malicious JavaScript that is then executed with elevated privileges inside the application.
OpenCVE Enrichment