CVE Feed

    Dashboard / CVE / CVE-2025-54871

    CVE-2025-54871

    Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unprivileged users to bypass macOS TCC privacy protections by enabling ELECTRON_RUN_AS_NODE. This environment variable allows arbitrary Node.js code to be executed via the -e flag, which runs inside the main Electron context, inheriting any previously granted TCC entitlements (such as access to Documents, Downloads, etc.). This issue is fixed in version 2.20.0.

    Published:Aug 5, 2025
    Last Modified:Oct 9, 2025
    EPS:Aug 5, 2025
    EPSS Score:0.00013
    CVSS Score:5.5

    Affected Products

    Vendor
    Electroncapture
    Product
    Electron Capture
    Vendor
    Steveseguin
    Product
    Electroncapture

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High