PT-2025-31890 · Unknown · Electroncapture

Swayzgl1Tzyyy

·

Published

2025-08-05

·

Updated

2025-08-05

·

CVE-2025-54871

CVSS v3.1
5.5
VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

Electron Capture versions 2.19.1 and below

Description:

Electron Capture facilitates video playback for screen-sharing and capture. The `elecap` app on macOS allows local unprivileged users to bypass macOS TCC privacy protections by enabling the `ELECTRON RUN AS NODE` environment variable. This allows arbitrary Node.js code to be executed via the `-e` flag, running inside the main Electron context and inheriting previously granted TCC entitlements, such as access to Documents and Downloads.

Recommendations:

Update to version 2.20.0 or later.

Exploit

Fix

LPE

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-54871
GHSA-8849-P3J4-JQ4H

Affected Products

Electroncapture