Web Hack List

Collected research

Allow arbitrary URLs, expect arbitrary code execution

Researchers found that desktop apps which pass user-controlled URLs to OS helpers such as QDesktopServices::openUrl can turn arbitrary URI schemes into one-click code execution. Across Nextcloud, Telegram, VLC, office suites, Mumble, wallets, Wireshark and WinSCP, remote-share mounting and unsafe protocol handlers opened executables; scheme allowlists and stronger OS warnings were recommended.

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.