Junglewise Threat Intelligence

CVE-2026-42184: Tauri origin confusion in is_local_url function on Windows and Android

CVE-2026-42184 · Severity: high · CVSS 8.8 · Published 2026-05-27

Technologies: tauri (crates.io). Vendors: crates.io.

Executive brief

Tauri is a framework used to build desktop and mobile applications with web technologies. A security flaw on Windows and Android allows malicious websites to trick the application into thinking they are part of the app's own internal code. This allows an attacker to execute restricted commands, potentially leading to unauthorized data access or control over the application's backend functions.

Technical details

An origin confusion vulnerability exists in Tauri's `is_local_url()` function on Windows and Android platforms. Due to WebView limitations, Tauri maps custom URI schemes to `http://<scheme>.localhost/`. The validation logic incorrectly uses `split_once('.')` on the domain and only checks if the first segment matches a registered protocol, failing to verify the remainder of the domain. An attacker can exploit this by hosting a malicious page on a domain like `http://app.attacker.com/`; if 'app' is a registered protocol, Tauri misclassifies the remote page as a trusted local origin. This allows the remote page to invoke IPC (Inter-Process Communication) commands that were intended to be restricted to the local frontend. The issue is patched in version 2.11.1.

Affected products

  • tauri-apps tauri >= 2.0.0, <= 2.11.0

Timeline

  • 2026-05-06: disclosed
  • 2026-05-06: advisory
  • 2026-05-06: patched: Fixed in version 2.11.1

References

Related threats