Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unprivileged users to bypass macOS TCC privacy protections by enabling ELECTRON_RUN_AS_NODE. This environment variable allows arbitrary Node.js code to be executed via the -e flag, which runs inside the main Electron context, inheriting any previously granted TCC entitlements (such as access to Documents, Downloads, etc.). This issue is fixed in version 2.20.0.
History

Tue, 05 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 05 Aug 2025 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Steveseguin
Steveseguin electroncapture
Vendors & Products Steveseguin
Steveseguin electroncapture

Tue, 05 Aug 2025 00:45:00 +0000

Type Values Removed Values Added
Description Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unprivileged users to bypass macOS TCC privacy protections by enabling ELECTRON_RUN_AS_NODE. This environment variable allows arbitrary Node.js code to be executed via the -e flag, which runs inside the main Electron context, inheriting any previously granted TCC entitlements (such as access to Documents, Downloads, etc.). This issue is fixed in version 2.20.0.
Title Electron Capture is Vulnerable to TCC Bypass via Misconfigured Node Fuses (macOS)
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-05T00:03:09.902Z

Updated: 2025-08-05T14:55:27.686Z

Reserved: 2025-07-31T17:23:33.473Z

Link: CVE-2025-54871

cve-icon Vulnrichment

Updated: 2025-08-05T14:55:20.536Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-05T01:15:43.010

Modified: 2025-08-05T15:15:31.897

Link: CVE-2025-54871

cve-icon Redhat

No data.