Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4926Taking note: XSS to RCE in the Simplenote Electron client XSS RCE Automattic Yasin Soliman (@SecurityYasin) Bug Bounty2017-11-222023-06-13
4677Vulnerability in Hangouts Chat a.k.a. how Electron makes open redirect great again Open redirect RCE Google Michał Bentkowski (@SecurityMB) Bug Bounty2018-07-242023-06-13
3217Open Sesame: Escalating Open Redirect to RCE with Electron Code Review Open redirect RCE Security code review NA Eugene Lim (@spaceraccoonsec) Bug Bounty2020-08-142023-06-13
2912A %27Novel%27 Way to Bypass Executable Signature Checks with Electron Local Privilege Escalation NA Parsia Hackerman (@cryptogangsta) Bug Bounty2021-01-082023-06-13
2362Bug Bounty Stories #1: Tale of CSP bypass in an electron app! CSP bypass NA SecurityGOAT (@RuntimeSecurity) Bug Bounty2021-07-312023-06-13
1209Critical Local File Read in Electron Desktop App LFI Asana Renwa (@RenwaX23) Bug Bounty2022-08-172023-06-13
1120Quasar: Compromising Electron Apps Local Privilege Escalation Microsoft Taggart (@mttaggart) Bug Bounty2022-09-062023-06-13
895Visual Studio Code Jupyter Notebook RCE RCE XSS Arbitrary file read Electron Microsoft Luca Carettoni (@lucacarettoni) Bug Bounty2022-10-272023-06-13
403Escaping well-configured VSCode extensions (for profit) Electron Webview Path traversal Microsoft Vasco Franco Bug Bounty2023-02-232023-06-13
304Vulnerabilities in the TPM 2.0 reference implementation code Memory corruption Out-of-bounds Read Out-of-bounds Write Microsoft VMware Google IBM Lenovo Qemu Nuvoton Trusted Computing Group STMicroelectronics Aruba Networks CERT/CC libtpms Francisco Falcon (@fdfalcon) Bug Bounty2023-03-142023-06-13