Collected research
Allow arbitrary URLs, expect arbitrary code execution
Researchers found that desktop apps which pass user-controlled URLs to OS helpers such as QDesktopServices::openUrl can turn arbitrary URI schemes into one-click code execution. Across Nextcloud, Telegram, VLC, office suites, Mumble, wallets, Wireshark and WinSCP, remote-share mounting and unsafe protocol handlers opened executables; scheme allowlists and stronger OS warnings were recommended.
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.