{"id":"CVE-2025-54871","summary":"Electron Capture is Vulnerable to TCC Bypass via Misconfigured Node Fuses (macOS)","details":"Electron Capture facilitates video playback for screen-sharing and capture. In versions 2.19.1 and below, the elecap app on macOS allows local unprivileged users to bypass macOS TCC privacy protections by enabling ELECTRON_RUN_AS_NODE. This environment variable allows arbitrary Node.js code to be executed via the -e flag, which runs inside the main Electron context, inheriting any previously granted TCC entitlements (such as access to Documents, Downloads, etc.). This issue is fixed in version 2.20.0.","aliases":["GHSA-8849-p3j4-jq4h"],"modified":"2026-08-12T03:51:47.031457537Z","published":"2025-08-05T00:03:09.902Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54871.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-284"]},"references":[{"type":"WEB","url":"https://github.com/steveseguin/electroncapture/releases/tag/2.20.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54871.json"},{"type":"ADVISORY","url":"https://github.com/steveseguin/electroncapture/security/advisories/GHSA-8849-p3j4-jq4h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54871"},{"type":"FIX","url":"https://github.com/steveseguin/electroncapture/commit/3837f54e75911bb99fa45cfa138a5e401d16f531"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/steveseguin/electroncapture","events":[{"introduced":"0"},{"fixed":"4d4cb9faa7dfed0b5176a8572c6dd2929d6b800b"},{"fixed":"3837f54e75911bb99fa45cfa138a5e401d16f531"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:electroncapture:electron_capture:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.20.0"}]}}],"versions":["2.19.1","2.19.0","2.18.9","2.18.8","2.18.7","2.15.5","2.18.x","2.18.1","2.18.0","2.17.11","2.17.10","2.17.9","2.17.8","2.17.7","2.17.6","2.17.5","2.17.4","2.17.3","2.17.2","2.17.1.1","2.17.1","2.17.0","2.16.2","2.16.1","2.16.0","2.15.3","2.15.2","2.15.0","2.14.1","2.14.0","2.13.1","2.13.0","2.12.1","2.11.0","2.10.0","1.1.2","1.1.1","1.1.0","1.0.9","1.0.8","1.0.7","1.0.6","1.05","1.03","1.02"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54871.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}