Collected research
ElectroVolt - Pwning Popular Desktop Apps
DEF CON 30 - Aaditya Purani, Max Garrett - ElectroVolt - Pwning Popular Desktop Apps
How an XSS in an Electron renderer is escalated to remote code execution: prototype pollution gadgets leak the internal IPC and remote modules, weak contextIsolation and nodeIntegration settings expose Node APIs, and misconfigured new-window handlers open unsandboxed windows. Demonstrated against Discord, Microsoft Teams, Notion and others.
Record
- Document
- DEF CON 30 - Aaditya Purani, Max Garrett - ElectroVolt - Pwning Popular Desktop Apps
- Researcher
- Mohan Sri Rama Krishna, Max Garrett, Aaditya Purani and William Bowling
- Published by
- i.blackhat.com
- Date
- Format
- Recording
- Topic
- Other
In the archive
Related sources
- ElectroVolt: Pwning Popular Desktop Apps While Uncovering New Attack Surface on Electron (Slides) Whitepaper
- Remote code execution on Discord Desktop
- Hacking Discord for $5000 Bounty
- ElectroVolt: Pwning popular desktop apps while uncovering new attack surface on Electron
- ElectroVolt: Pwning Popular Desktop Apps While Uncovering New Attack Surface on Electron
- ElectroVolt Pwning Desktop Apps Built On Electron by Mohan Sri Rama | Nullcon Goa 2022
Tags
This page is the archive's own catalogue record. The research is the work of Mohan Sri Rama Krishna, Max Garrett, Aaditya Purani and William Bowling, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .