Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2022-23597: Remote code execution on Element Desktop

Summary

Full RCE on Element Desktop achieved by chaining iframe injection, Electron misconfigurations, and a V8 exploit to escape the sandbox and reach Node.js APIs from a compromised subframe.
CVE
CVE-2022-23597
Published
Collected

original ↗