Executive brief
Mattermost Desktop App, a messaging platform client for Windows, Mac, and Linux, fails to properly restrict screen capture functionality. An attacker can exploit this to silently capture high-quality screenshots via JavaScript APIs, potentially exposing sensitive conversation content, credentials, or other confidential information displayed on screen without user awareness or consent.
Technical details
The vulnerability is a missing access control issue (CWE-284) in Mattermost Desktop App versions ≤5.8.0 that fails to enforce restrictions on screen capture APIs accessible via JavaScript. An attacker with code execution capability (e.g., through malicious JavaScript injection or a compromised plugin) can invoke screen capture functionality without triggering user notifications or permission prompts, enabling silent capture of high-quality screenshots of application content. The attack requires network access and does not require user interaction or elevated privileges. The vulnerability is fixed in version 5.9.0 and later. Patches are available and users should upgrade immediately to mitigate exposure of sensitive chat content and information.
Affected products
- Mattermost Mattermost Desktop App 0 through 5.8.0
Timeline
- 2024-09-16: disclosed
- 2024-09-16: patched: Fix available in version 5.9.0