Home

Description

An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor disputes this because it requires local access to a victim's machine.

PUBLISHED Reserved 2024-01-21 | Published 2024-01-28 | Updated 2024-10-18 | Assigner mitre

References

github.com/V3x0r/CVE-2024-23742

www.electronjs.org/blog/statement-run-as-node-cves

cve.org (CVE-2024-23742)

nvd.nist.gov (CVE-2024-23742)

Download JSON