CVE-2025-14498: TradingView Desktop Electron Uncontrolled Search Path Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of TradingView Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of the Electron framework. The product loads a script file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of a target user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14498?
CVE-2025-14498 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-14498?
To mitigate CVE-2025-14498, ensure that you update to the latest version of TradingView Desktop provided by the vendor.
Who is affected by CVE-2025-14498?
CVE-2025-14498 affects users of TradingView Desktop that have not applied the latest security updates.
What can an attacker do if they exploit CVE-2025-14498?
If exploited, CVE-2025-14498 allows attackers to escalate their privileges on the affected system.
What are the prerequisites for exploiting CVE-2025-14498?
An attacker must first have the ability to execute low-privileged code on the target system to exploit CVE-2025-14498.