Junglewise Threat Intelligence

CVE-2026-92299: Jitsi Electron SDK screen sharing enumeration without user consent

CVE-2026-92299 · Severity: high · CVSS 7.4 · Published 2026-09-16

Executive brief

Jitsi's Electron SDK for building desktop video conferencing applications contains a flaw that allows malicious JavaScript code running in a meeting page to enumerate all connected screens and windows without user knowledge or permission. An attacker injecting code into a meeting can retrieve detailed thumbnails and metadata about what's displayed on a user's monitor without triggering any OS-level permission prompts or requiring explicit user consent, potentially exposing sensitive information visible on other screens.

Technical details

The vulnerability is a missing authorization check in the getDesktopSources() function exposed via the Electron contextBridge. The function allows any script executing in the renderer process to call the jitsi-screen-sharing-get-sources IPC route to list and capture desktop sources without requiring an active getDisplayMedia() picker (which normally enforces OS-level user consent). Affected versions prior to 10.0.5 expose this capability directly, bypassing both application-level authorization and OS-level permission gates. An attacker with code execution in the meeting page renderer can enumerate screens and retrieve thumbnails at arbitrary resolutions. The fix involves restricting access to this IPC route to require an active user-initiated getDisplayMedia() picker or implementing proper authorization checks.

Affected products

  • Jitsi Electron SDK before 10.0.5

Timeline

  • 2026-09-16: disclosed

References