CVE-2020-12079: Beakerbrowser Beaker
Critical severity, CVSS 10.0. EPSS: 2.2% chance of exploitation in the next 30 days.
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron internal messaging API.
Affected products
- Beakerbrowser Beaker: before 0.8.9 (fixed in 0.8.9)
Published 2020-04-23. Last modified 2026-06-17.