Executive brief
The Tauri updater plugin allows frontend JavaScript code to bypass rollback protection by setting an allowDowngrades parameter to true, which disables version checks. An attacker exploiting an XSS vulnerability in a Tauri application can invoke this to downgrade the app to an older, vulnerable version without needing to fake a higher version number. This could allow installation of malicious code or restoration of patched vulnerabilities.
Technical details
The updater's 'check' IPC command accepts an allowDowngrades boolean parameter from untrusted frontend code, which bypasses the normal "update must be newer" version comparator. Default permissions grant allow-check to the webview, so any XSS in the frontend can trigger downgrade attacks. When combined with a secondary vulnerability, this enables full rollback without version spoofing.
Affected products
- Tauri tauri-plugin-updater
Timeline
- 2026-09-22: disclosed: CVE-2026-95624 published