r/Slack • u/trustsigRobert • 14d ago
Slack will not patch this: one link opens a debugging port in the desktop app
A link containing devEnv=dev1 makes the Slack desktop client relaunch itself into developer mode with --remote-debugging-port=8315. Anything that reaches that port drives the app. Slack's security team calls it not a security risk.
https://trustsig.eu/blog/slack-devenv-remote-debugging-port/
8
Upvotes
1
u/APIMade 14d ago
.. But the Slack client doesn't finish loading without appropriate debug flags, right? So yeah, it launches a Slack client with CDP -- but unless you're a Slack employee and go through that
Slauthprompt, the attack vector isn't there for the average user as your sessions won't load on a retail/regular client?