{"slug": "turning-cluely-into-malware", "title": "Turning Cluely into Malware", "summary": "Security researchers at Hacktron disclosed a vulnerability chain in the Electron-based AI assistant Cluely, found in July 2025, that let a malicious page loaded in the app's renderer process silently capture screenshots of the victim's entire screen and record microphone audio. The chain began with the main window lacking a `will-navigate` handler, so clicking a link in an AI markdown response navigated the app to an attacker-controlled URL, and a preload script exposed an unfiltered IPC bridge allowing calls to any channel name. The researchers published the analysis months later as an educational resource for developers building Electron-based AI agents, noting they had not tracked Cluely's development since and that its security posture may have improved.", "body_md": "## Note\n\nWe found this vulnerability back in **July 2025** and were lazy to publish at\nthe time. We’re sharing it now, months later, purely as an educational\nresource for developers building Electron-based AI agents. Everything in this\npost is based on our analysis of Cluely as it existed back then. We have not\nbeen following Cluely’s development since, and for all we know they may have\nsignificantly improved their security posture and practices.\n\nIn continuation of our series on **[Hacking AI Agents](https://www.hacktron.ai/blog/hacking-openai-atlas-browser)**, we are back again, this time looking at **Cluely**, the AI-powered assistant that watches your screen, listens to your mic, and helps you ace interviews, meetings, and more.\n\nAI agents are everywhere now, writing code, watching your screen, listening to your mic. They have deep access to your machine by design. But that same access makes them a juicy target. What if someone could turn that helpful AI agent against you?\n\nToday we’re walking through a vulnerability we found in Cluely back in mid-2025, and showing what can go wrong when Electron apps with deep system access don’t get the security basics right. We have a long history with Electron security, a few years back we published research at [DEF CON 30](https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/Aaditya%20Purani%20-%20ElectroVolt%20Pwning%20popular%20desktop%20apps%20while%20uncovering%20new%20attack%20surface%20on%20Electron.pdf) that let us pwn almost every major Electron app at the time, including Discord.\n\n## What is Cluely?\n\nCluely is an Electron-based desktop app that acts as an AI overlay on your screen. It captures your screen and microphone audio to provide real-time AI assistance during interviews, meetings, and more. The app is designed to be *undetectable*, it hides from screen sharing, mission control, and taskbar visibility.\n\nUnder the hood it’s a standard Electron app with a React frontend, using `react-markdown` to render AI responses and `@deepgram/sdk` for real-time transcription.\n\n## The Attack Surface\n\nSince Cluely is an Electron app with access to your screen and microphone by design, the security stakes are high. If an attacker can execute code within the Electron renderer process, they inherit all of those capabilities. Let’s walk through the vulnerability chain.\n\n### Step 1: No Navigation Guard on the Main Window\n\nCluely uses `react-markdown` to render the AI’s responses. There’s no obvious XSS, the markdown renderer sanitizes output properly. But links still get rendered as clickable `<a>` tags, and here’s where it gets interesting.\n\nElectron apps are supposed to handle navigation events with a `will-navigate` handler to prevent the renderer from navigating to arbitrary URLs. Looking at the Cluely source, we can see that the `DisplayOverlay` class *does* have this protection:\n\nBut the **main window**, the one that actually renders AI responses with clickable links, has **no such protection**. Looking at the base `Window` class:\n\nSo when a user clicks any link rendered in the AI’s markdown response, instead of opening it in the system browser, it **navigates the entire Electron app to that URL**. The malicious page now loads directly inside Cluely’s renderer process.\n\n### Step 2: Juicy IPC Exposed via Preload\n\nSo we went hunting for what we could do from the renderer. Turns out there’s some juicy IPC exposed.\n\nThe preload script exposes the Electron IPC interface directly to the renderer:\n\nWhat we are looking at is a **wide-open IPC bridge**. There’s no allowlist filtering on channel names. Any page loaded in the renderer can call `window.electron.ipcRenderer.send()` or `window.electron.ipcRenderer.invoke()` with **any** channel name.\n\nNow look at what IPC handlers the main process registers:\n\nThis means from the malicious page now running inside the renderer, we can silently:\n\n1. **Capture screenshots** of the victim’s entire screen\n2. **Record audio** from the native recorder (screen audio)\n3. **Monitor the microphone** , capturing everything the user says\n\nAnd exfiltrate all of it to our server.\n\n### Step 3: Sandbox Disabled -> RCE\n\nBut it gets worse. Looking at the `webPreferences`, there’s no `sandbox: true`:\n\nNow this is bad, without the sandbox, the renderer runs outside the Chromium sandbox, which means a [V8 exploit](https://www.hacktron.ai/blog/i-let-claude-opus-to-write-me-a-chrome-exploit) in the renderer leads straight to full remote code execution on the victim’s machine. We’re not going to walk through that exploit chain in this post, but we did exactly this on Discord. You can read the full writeup here: **[Remote Code Execution on Discord Desktop](https://www.hacktron.ai/blog/discord-rce)**.\n\nThe Discord RCE video shows a full reverse shell popping from inside an Electron app, the same attack would work on Cluely:\n\nSo the missing `will-navigate` handler leads to screen and audio leaks with an easy path and then a full RCE via v8 exploit.\n\n## Prompt Injection as the Entry Point\n\nNow to actually exploit this, we need to get a malicious link rendered on the user’s Cluely window while they’re in a meeting. There are many ways to pull this off, [indirect prompt injection](https://www.hacktron.ai/blog/rce-in-vscode-copilot) being one of them. For example, consider a scenario where the user is using Cluely during an interview. The interviewer’s task or question contains a crafted prompt injection that causes the AI to render a link:\n\nThe AI renders this as a clickable link in its markdown response. The user clicks it, thinking it’s part of the task. The link navigates the entire Cluely app to our malicious page, and the exploit fires automatically.\n\n## The Exploit\n\nHere’s the PoC video before we dive into the code:\n\nHere’s the proof of concept that runs inside Cluely after navigation. On page load it silently takes a screenshot and records 10 seconds of audio:\n\nWhen this page loads inside Cluely, the `window.electron.ipcRenderer` bridge is available. The exploit invokes `capture-screenshot` to grab a screenshot and sends `mac-set-native-recorder-enabled` to start recording audio. The attacker gets a screenshot of the victim’s desktop and a recording of everything being said, all without any user prompt or permission dialog.\n\n## The Impact\n\nAny Cluely user was vulnerable. If an attacker could get the AI to render a malicious link (via prompt injection or social engineering), and the user clicked it, the attacker could:\n\n- **Full Remote Code Execution** : the unsandboxed renderer means a V8 exploit gives the attacker a shell on the victim’s machine, exactly like[our Discord RCE](https://www.hacktron.ai/blog/discord-rce) . Install backdoors, exfiltrate files, persist across reboots, everything.\n- **Capture screenshots** of the victim’s entire screen, including sensitive documents, credentials, and private conversations\n- **Record audio** from the system recorder, capturing meeting discussions, interviews, and ambient conversations\n- **Monitor the microphone** , turning Cluely into a silent surveillance tool\n\nAnd even without going the V8 exploit route, the exposed IPC bridge already gives you the screen and mic for free.\n\nThe irony: an app designed to help you cheat undetectably could be turned into actual malware that spies on you, or owns your entire machine, undetectably.\n\n## The Root Causes\n\nThere are three compounding issues:\n\n1. \n**Missing `will-navigate` handler** : The main window allows in-app navigation to arbitrary URLs. The fix is one line: intercept the`will-navigate` event and either block it or open the URL in the system browser.\n2. \n**Overly permissive IPC bridge** : The preload script exposes`send` ,`invoke` , and`on` without any channel filtering. Any page loaded in the renderer can call any IPC handler. The preload should use an allowlist of channels that the renderer legitimately needs.\n3. \n**No sandbox = RCE** : The renderer process runs without a sandbox. Combined with the missing`will-navigate` , this is a direct path to full remote code execution via a V8 exploit, the[same attack class we used on Discord](https://www.hacktron.ai/blog/discord-rce) . This elevates the vulnerability from a data leak to a complete system compromise.\n\n## Disclosure & Timeline\n\nWe discovered this in **July 2025**. At the time, Cluely didn’t have a vulnerability disclosure program. We tried reaching out through multiple channels and eventually made contact. The issue was silently patched, no acknowledgment, no credit.\n\nCredits and acknowledgements aside, who cares. But, for all the AI startups out there: **have a vulnerability disclosure program.** Let researchers report bugs to you. Treat them with recognition and good faith. That’s really all it takes.\n\nFor everyone else: there are a lot of AI startups building agents that have deep access to your machine, your screen, your mic, your files, your clipboard. Maybe don’t install random shit. We previously hacked [Windsurf](https://www.hacktron.ai/blog/vscode-rce), [Perplexity Comet](https://www.hacktron.ai/blog/perplexity-comet-uxss), [OpenAI Atlas](https://www.hacktron.ai/blog/hacking-openai-atlas-browser), and [Google’s Antigravity](https://www.hacktron.ai/blog/Hacking-google-antigravity).\n\nSo don’t be surprised if you find an email from us in your inbox at some point.\n\n## About Us\n\nOur security research team is world-class: top-ranked CTF competitors, DEF CON-published researchers, and leading bug bounty hunters. We’ve hacked browsers, operating systems, mobile apps, desktop software, and massive web platforms.\n\nChances are, you’ve used something we’ve helped make more secure.\n\nWe’re now channeling that expertise into Hacktron: AI agents and us working together to bring that real offensive capability into every stage of the software lifecycle.\n\nIf you’re looking to secure your agentic applications, we can help. We’ve hacked Cluely, Cursor, Windsurf, Perplexity Comet, OpenAI Atlas, and Google’s Antigravity, and many more. We work closely with teams to secure agentic systems before attackers find what we find.\n\nMeet our team at [hacktron.ai](https://hacktron.ai). Reach out at [hello@hacktron.ai](mailto:hello@hacktron.ai) or [app.hacktron.ai/contact](https://app.hacktron.ai/contact).", "url": "https://wpnews.pro/news/turning-cluely-into-malware", "canonical_source": "https://www.hacktron.ai/blog/hacking-cluely", "published_at": "2026-10-02 18:54:31+00:00", "updated_at": "2026-10-02 19:06:15.803081+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "artificial-intelligence"], "entities": ["Cluely", "Hacktron", "Electron", "React", "react-markdown", "@deepgram/sdk", "DEF CON 30", "Discord"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/turning-cluely-into-malware", "markdown": "https://wpnews.pro/news/turning-cluely-into-malware.md", "text": "https://wpnews.pro/news/turning-cluely-into-malware.txt", "jsonld": "https://wpnews.pro/news/turning-cluely-into-malware.jsonld"}}