CVE-2022-23597: Remote code execution on Element Desktop
hacktron.ai | vulnerability | CVE-2022-23597 | #rce | #vulnerability-research | #sandbox-escape | #v8 | #electron | #cve-2022-23597 | #element-desktop
Summary
Full RCE on Element Desktop achieved by chaining iframe injection, Electron misconfigurations, and a V8 exploit to escape the sandbox and reach Node.js APIs from a compromised subframe.
- CVE
- CVE-2022-23597
- Published
- Collected
Skip to content