CVE-2026-92299
Received Received - Intake

Jitsi Electron SDK Screen Enumeration Flaw

Vulnerability report for CVE-2026-92299, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: VulnCheck

Description

@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in the meeting page to enumerate screens and windows. Attackers can call the jitsi-screen-sharing-get-sources IPC route to retrieve desktop thumbnails at arbitrary resolution without user consent or operating system permission prompts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jitsi jitsi_meet_electron_sdk to 10.0.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in @jitsi/electron-sdk before version 10.0.5 allows any script in a meeting page to access screen-sharing sources without user consent. The getDesktopSources() function is exposed via contextBridge, enabling attackers to call the jitsi-screen-sharing-get-sources IPC route and retrieve desktop thumbnails at any resolution without OS-level permission prompts.

Detection Guidance

Check if your application uses @jitsi/electron-sdk versions before 10.0.5. Inspect Electron app logs for unauthorized calls to jitsi-screen-sharing-get-sources IPC route or getDesktopSources(). Monitor network traffic for unexpected screen thumbnail requests.

Impact Analysis

An attacker could exploit this to capture sensitive information displayed on your screen during a Jitsi meeting without your knowledge. This includes private documents, emails, or other confidential content visible on your desktop or applications.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles and HIPAA's requirements for safeguarding protected health information. Organizations using affected versions may face compliance violations and legal consequences.

Mitigation Strategies

Upgrade to @jitsi/electron-sdk version 10.0.5 or later immediately. Disable screen sharing features if not required. Implement strict input validation for IPC routes in Electron apps. Review Electron security guidelines for context isolation and sandboxing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92299. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart