PT-2025-31890 · Unknown · Electroncapture

Swayzgl1Tzyyy

·

Published

2025-08-05

·

Updated

2025-10-09

·

CVE-2025-54871

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Electron Capture versions 2.19.1 and below
Description Electron Capture facilitates video playback for screen-sharing and capture. The elecap app on macOS allows local unprivileged users to bypass macOS TCC (Transparency, Consent, and Control) privacy protections by enabling the ELECTRON RUN AS NODE environment variable. This variable allows arbitrary Node.js code to be executed via the -e flag, which runs inside the main Electron context, inheriting any previously granted TCC entitlements (such as access to Documents, Downloads, etc.).
Recommendations Update to version 2.20.0 or later.

Exploit

Fix

LPE

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-54871
GHSA-8849-P3J4-JQ4H

Affected Products

Electroncapture