Preliminary research
New Architecture, New Risks: One Click to Pwn IDIS IP Cameras
AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
A malicious site connects to an IDIS desktop client's localhost WebSocket because the service does not validate Origin. Recovering the protocol's constant key and injecting Chromium's `--utility-cmd-prefix` argument through the launcher yields one-click host command execution.
Record
- Researcher
- Vera Mens
- Published by
- Claroty
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Vera Mens, first published at the original source. Preserved copies are kept so the citation survives its host.