Researchers disclosed a remote code execution chain against Discord Desktop that combined a cross-site scripting flaw in Discord embeds, a Chromium content security policy bypass, and a V8 engine vulnerability to achieve code execution on the client. The attack began with XSS in a Vimeo embed rendered inside Discord, then used an older Chromium CSP bypass to load attacker-controlled content despite Vimeo’s restrictive policy. The write-up says Discord Desktop was running Electron 9 with Chromium 83, with nodeIntegration disabled and contextIsolation enabled, but without an explicit sandbox=true setting on the main window.
The researchers then abused Discord’s handling of the new-window event and redirect behavior to obtain an unsandboxed renderer, creating the conditions needed to exploit a known V8 issue tracked as Chromium bug 1196683 and reach code execution. The report credits collaboration with Harsh Jaiswal and ptrYudai, and links the exploit chain to a V8 code review reference associated with the underlying browser-engine bug. Discord later mitigated the issue by upgrading Electron and fixing the new-window configuration so external sites could no longer load in unsafe new windows.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A Chromium Gerrit review was created for change 2820971 in the V8 project, corresponding to the bug later referenced by the Discord RCE research as Chromium bug 1196683.
After the research, Discord updated Electron and corrected the new-window misconfiguration so external sites could no longer load in new windows, blocking the exploit chain described in the write-up.
Using the embed XSS, CSP bypass, Discord's unsafe new-window behavior, and the V8 bug 1196683 with help from ptrYudai, the researchers achieved remote code execution against Discord Desktop.
The researcher, working with Harsh Jaiswal, found a cross-site scripting issue in a Vimeo embed rendered by the Discord desktop application and chained it with an old Chromium CSP bypass to load attacker-controlled content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.