Turning Cluely into Malware Security researchers at Hacktron disclosed a vulnerability chain in the Electron-based AI assistant Cluely, found in July 2025, that let a malicious page loaded in the app's renderer process silently capture screenshots of the victim's entire screen and record microphone audio. The chain began with the main window lacking a `will-navigate` handler, so clicking a link in an AI markdown response navigated the app to an attacker-controlled URL, and a preload script exposed an unfiltered IPC bridge allowing calls to any channel name. The researchers published the analysis months later as an educational resource for developers building Electron-based AI agents, noting they had not tracked Cluely's development since and that its security posture may have improved. Note We found this vulnerability back in July 2025 and were lazy to publish at the time. We’re sharing it now, months later, purely as an educational resource for developers building Electron-based AI agents. Everything in this post is based on our analysis of Cluely as it existed back then. We have not been following Cluely’s development since, and for all we know they may have significantly improved their security posture and practices. In continuation of our series on Hacking AI Agents https://www.hacktron.ai/blog/hacking-openai-atlas-browser , we are back again, this time looking at Cluely , the AI-powered assistant that watches your screen, listens to your mic, and helps you ace interviews, meetings, and more. AI agents are everywhere now, writing code, watching your screen, listening to your mic. They have deep access to your machine by design. But that same access makes them a juicy target. What if someone could turn that helpful AI agent against you? Today we’re walking through a vulnerability we found in Cluely back in mid-2025, and showing what can go wrong when Electron apps with deep system access don’t get the security basics right. We have a long history with Electron security, a few years back we published research at DEF CON 30 https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/Aaditya%20Purani%20-%20ElectroVolt%20Pwning%20popular%20desktop%20apps%20while%20uncovering%20new%20attack%20surface%20on%20Electron.pdf that let us pwn almost every major Electron app at the time, including Discord. What is Cluely? Cluely is an Electron-based desktop app that acts as an AI overlay on your screen. It captures your screen and microphone audio to provide real-time AI assistance during interviews, meetings, and more. The app is designed to be undetectable , it hides from screen sharing, mission control, and taskbar visibility. Under the hood it’s a standard Electron app with a React frontend, using react-markdown to render AI responses and @deepgram/sdk for real-time transcription. The Attack Surface Since Cluely is an Electron app with access to your screen and microphone by design, the security stakes are high. If an attacker can execute code within the Electron renderer process, they inherit all of those capabilities. Let’s walk through the vulnerability chain. Step 1: No Navigation Guard on the Main Window Cluely uses react-markdown to render the AI’s responses. There’s no obvious XSS, the markdown renderer sanitizes output properly. But links still get rendered as clickable