External risk intelligence

Bilibili Desktop Code Execution Vulnerability in bili-inject.js and bili-bridge.js

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-75357

The vulnerability affects a desktop application (Bilibili Desktop), which is client-side software designed for end-user systems. Such applications are typically not intended for public internet exposure, edge services, or network-reachable infrastructure, making remote exploitation via common internet-facing attack surfaces very unlikely.

Code Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability discovered in the Bilibili Desktop application that could allow a remote attacker to execute arbitrary code. While the technical details involve specific software components, the potential for remote code execution signifies a serious security concern that warrants executive attention to understand its potential relevance to the organization.

  • Remote code execution flaw in desktop software.
  • Critical flaw could compromise user systems.
  • Confirm relevance to our user base.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted data to the Bilibili Desktop application over the network. This could lead to the execution of arbitrary code on the user's system, allowing the attacker to take control of the application and potentially the entire device.

  • No authentication needed.
  • Network-accessible vulnerable component.
  • Arbitrary code execution possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a remote attacker to execute arbitrary code on affected systems by exploiting vulnerabilities in the bili-inject.js and bili-bridge.js components of Bilibili Desktop. Such an attack could potentially compromise the integrity and availability of the affected system, and access sensitive information.

  • System code execution.
  • Via network injection.
  • Compromise system integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects the Bilibili Desktop application, indicating that ownership likely resides with teams managing end-user endpoint security and application deployment. The first practical step involves identifying all instances of the affected software within the environment, determining their business criticality and network exposure, and then assigning the appropriate team for remediation planning and execution.

  • Endpoint security and app owners.
  • Verify app reachability and criticality.
  • Plan remediation with affected owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Bilibili Desktop?

Bilibili Desktop is a client-side application used by individuals to access the Bilibili video-sharing platform from their personal computers. It serves as a dedicated interface for viewing content rather than a server-side service, meaning it runs locally on a user's machine to handle media playback and interaction features.

What does CVE-2026-75357 mean?

This vulnerability is classified as CWE-94, which refers to Improper Control of Generation of Code. In plain terms, it means the application processes incoming data in an unsafe way that allows an attacker to inject and execute their own unauthorized commands. It essentially tricks the software into running malicious instructions as if they were part of the legitimate program.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending specially crafted data over the network to the vulnerable bili-inject.js and bili-bridge.js components. It is important to note that simply having the application installed is not enough; the software must be actively running and configured to receive network input. Standard local usage that does not involve network-based interaction with these specific components does not trigger the execution.

Is my organization at risk from this CVE?

According to Halo Surface Signal, this vulnerability is very unlikely to be exploited remotely. Because Bilibili Desktop is client-side software designed for end-user systems, it is generally not exposed to the public internet or used as an edge service. Risk is concentrated on individual user devices rather than network-reachable infrastructure, making broad organizational exposure quite low.

Do I need to take immediate action?

Your first step should be to identify where Bilibili Desktop is installed within your environment. Once you have a list of affected endpoints, coordinate with your endpoint security teams to monitor these devices. Since this is a desktop application, focus on internal system management rather than perimeter network defenses to ensure these assets are properly accounted for and updated if a fix becomes available.

References