CVE-2020-10858
Published Feb 5, 2021Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.
Vendor/product archive
2 CVEs tagged to zulip / zulip_desktop — 1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.
Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.