# Turning Cluely into Malware

> Source: <https://www.hacktron.ai/blog/hacking-cluely>
> Published: 2026-10-02 18:54:31+00:00

## Note

We found this vulnerability back in **July 2025** and were lazy to publish at
the time. We’re sharing it now, months later, purely as an educational
resource for developers building Electron-based AI agents. Everything in this
post is based on our analysis of Cluely as it existed back then. We have not
been following Cluely’s development since, and for all we know they may have
significantly improved their security posture and practices.

In continuation of our series on **[Hacking AI Agents](https://www.hacktron.ai/blog/hacking-openai-atlas-browser)**, we are back again, this time looking at **Cluely**, the AI-powered assistant that watches your screen, listens to your mic, and helps you ace interviews, meetings, and more.

AI agents are everywhere now, writing code, watching your screen, listening to your mic. They have deep access to your machine by design. But that same access makes them a juicy target. What if someone could turn that helpful AI agent against you?

Today we’re walking through a vulnerability we found in Cluely back in mid-2025, and showing what can go wrong when Electron apps with deep system access don’t get the security basics right. We have a long history with Electron security, a few years back we published research at [DEF CON 30](https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/Aaditya%20Purani%20-%20ElectroVolt%20Pwning%20popular%20desktop%20apps%20while%20uncovering%20new%20attack%20surface%20on%20Electron.pdf) that let us pwn almost every major Electron app at the time, including Discord.

## What is Cluely?

Cluely is an Electron-based desktop app that acts as an AI overlay on your screen. It captures your screen and microphone audio to provide real-time AI assistance during interviews, meetings, and more. The app is designed to be *undetectable*, it hides from screen sharing, mission control, and taskbar visibility.

Under the hood it’s a standard Electron app with a React frontend, using `react-markdown` to render AI responses and `@deepgram/sdk` for real-time transcription.

## The Attack Surface

Since Cluely is an Electron app with access to your screen and microphone by design, the security stakes are high. If an attacker can execute code within the Electron renderer process, they inherit all of those capabilities. Let’s walk through the vulnerability chain.

### Step 1: No Navigation Guard on the Main Window

Cluely uses `react-markdown` to render the AI’s responses. There’s no obvious XSS, the markdown renderer sanitizes output properly. But links still get rendered as clickable `<a>` tags, and here’s where it gets interesting.

Electron apps are supposed to handle navigation events with a `will-navigate` handler to prevent the renderer from navigating to arbitrary URLs. Looking at the Cluely source, we can see that the `DisplayOverlay` class *does* have this protection:

But the **main window**, the one that actually renders AI responses with clickable links, has **no such protection**. Looking at the base `Window` class:

So when a user clicks any link rendered in the AI’s markdown response, instead of opening it in the system browser, it **navigates the entire Electron app to that URL**. The malicious page now loads directly inside Cluely’s renderer process.

### Step 2: Juicy IPC Exposed via Preload

So we went hunting for what we could do from the renderer. Turns out there’s some juicy IPC exposed.

The preload script exposes the Electron IPC interface directly to the renderer:

What we are looking at is a **wide-open IPC bridge**. There’s no allowlist filtering on channel names. Any page loaded in the renderer can call `window.electron.ipcRenderer.send()` or `window.electron.ipcRenderer.invoke()` with **any** channel name.

Now look at what IPC handlers the main process registers:

This means from the malicious page now running inside the renderer, we can silently:

1. **Capture screenshots** of the victim’s entire screen
2. **Record audio** from the native recorder (screen audio)
3. **Monitor the microphone** , capturing everything the user says

And exfiltrate all of it to our server.

### Step 3: Sandbox Disabled -> RCE

But it gets worse. Looking at the `webPreferences`, there’s no `sandbox: true`:

Now this is bad, without the sandbox, the renderer runs outside the Chromium sandbox, which means a [V8 exploit](https://www.hacktron.ai/blog/i-let-claude-opus-to-write-me-a-chrome-exploit) in the renderer leads straight to full remote code execution on the victim’s machine. We’re not going to walk through that exploit chain in this post, but we did exactly this on Discord. You can read the full writeup here: **[Remote Code Execution on Discord Desktop](https://www.hacktron.ai/blog/discord-rce)**.

The Discord RCE video shows a full reverse shell popping from inside an Electron app, the same attack would work on Cluely:

So the missing `will-navigate` handler leads to screen and audio leaks with an easy path and then a full RCE via v8 exploit.

## Prompt Injection as the Entry Point

Now to actually exploit this, we need to get a malicious link rendered on the user’s Cluely window while they’re in a meeting. There are many ways to pull this off, [indirect prompt injection](https://www.hacktron.ai/blog/rce-in-vscode-copilot) being one of them. For example, consider a scenario where the user is using Cluely during an interview. The interviewer’s task or question contains a crafted prompt injection that causes the AI to render a link:

The AI renders this as a clickable link in its markdown response. The user clicks it, thinking it’s part of the task. The link navigates the entire Cluely app to our malicious page, and the exploit fires automatically.

## The Exploit

Here’s the PoC video before we dive into the code:

Here’s the proof of concept that runs inside Cluely after navigation. On page load it silently takes a screenshot and records 10 seconds of audio:

When this page loads inside Cluely, the `window.electron.ipcRenderer` bridge is available. The exploit invokes `capture-screenshot` to grab a screenshot and sends `mac-set-native-recorder-enabled` to start recording audio. The attacker gets a screenshot of the victim’s desktop and a recording of everything being said, all without any user prompt or permission dialog.

## The Impact

Any Cluely user was vulnerable. If an attacker could get the AI to render a malicious link (via prompt injection or social engineering), and the user clicked it, the attacker could:

- **Full Remote Code Execution** : the unsandboxed renderer means a V8 exploit gives the attacker a shell on the victim’s machine, exactly like[our Discord RCE](https://www.hacktron.ai/blog/discord-rce) . Install backdoors, exfiltrate files, persist across reboots, everything.
- **Capture screenshots** of the victim’s entire screen, including sensitive documents, credentials, and private conversations
- **Record audio** from the system recorder, capturing meeting discussions, interviews, and ambient conversations
- **Monitor the microphone** , turning Cluely into a silent surveillance tool

And even without going the V8 exploit route, the exposed IPC bridge already gives you the screen and mic for free.

The irony: an app designed to help you cheat undetectably could be turned into actual malware that spies on you, or owns your entire machine, undetectably.

## The Root Causes

There are three compounding issues:

1. 
**Missing `will-navigate` handler** : The main window allows in-app navigation to arbitrary URLs. The fix is one line: intercept the`will-navigate` event and either block it or open the URL in the system browser.
2. 
**Overly permissive IPC bridge** : The preload script exposes`send` ,`invoke` , and`on` without any channel filtering. Any page loaded in the renderer can call any IPC handler. The preload should use an allowlist of channels that the renderer legitimately needs.
3. 
**No sandbox = RCE** : The renderer process runs without a sandbox. Combined with the missing`will-navigate` , this is a direct path to full remote code execution via a V8 exploit, the[same attack class we used on Discord](https://www.hacktron.ai/blog/discord-rce) . This elevates the vulnerability from a data leak to a complete system compromise.

## Disclosure & Timeline

We discovered this in **July 2025**. At the time, Cluely didn’t have a vulnerability disclosure program. We tried reaching out through multiple channels and eventually made contact. The issue was silently patched, no acknowledgment, no credit.

Credits and acknowledgements aside, who cares. But, for all the AI startups out there: **have a vulnerability disclosure program.** Let researchers report bugs to you. Treat them with recognition and good faith. That’s really all it takes.

For everyone else: there are a lot of AI startups building agents that have deep access to your machine, your screen, your mic, your files, your clipboard. Maybe don’t install random shit. We previously hacked [Windsurf](https://www.hacktron.ai/blog/vscode-rce), [Perplexity Comet](https://www.hacktron.ai/blog/perplexity-comet-uxss), [OpenAI Atlas](https://www.hacktron.ai/blog/hacking-openai-atlas-browser), and [Google’s Antigravity](https://www.hacktron.ai/blog/Hacking-google-antigravity).

So don’t be surprised if you find an email from us in your inbox at some point.

## About Us

Our security research team is world-class: top-ranked CTF competitors, DEF CON-published researchers, and leading bug bounty hunters. We’ve hacked browsers, operating systems, mobile apps, desktop software, and massive web platforms.

Chances are, you’ve used something we’ve helped make more secure.

We’re now channeling that expertise into Hacktron: AI agents and us working together to bring that real offensive capability into every stage of the software lifecycle.

If you’re looking to secure your agentic applications, we can help. We’ve hacked Cluely, Cursor, Windsurf, Perplexity Comet, OpenAI Atlas, and Google’s Antigravity, and many more. We work closely with teams to secure agentic systems before attackers find what we find.

Meet our team at [hacktron.ai](https://hacktron.ai). Reach out at [hello@hacktron.ai](mailto:hello@hacktron.ai) or [app.hacktron.ai/contact](https://app.hacktron.ai/contact).
