A vulnerability has been identified in a prior version of the installer for Kobo Desktop App regarding, which could allow a malicious DLL in the same directory as the installer to be loaded. As a result, malicious arbitrary code could be executed with the privileges of the user who performed the installation.
At this time, Rakuten Kobo has not found any indication or evidence that this vulnerability has actually been exploited. This notice is provided as part of our ongoing proactive product security efforts.
Applicable Software
Kobo Desktop App Versions prior to July 15, 2026
Applicable OS
Windows (macOS is not affected)
For customers who are about to download and use the Kobo Desktop App installer from our website:
- This vulnerability was limited to the app installer and not the app itself.
- If you have downloaded the installer prior to July 15, 2026, you are recommended to permanently delete the installer and to download the latest version of the installer here: Download Kobo Desktop
Maintaining good digital habits is essential to protect your devices. Always make sure you have active, trusted antivirus and anti-malware software installed on your systems. Keep your operating system, web browsers, and applications updated to fix known security issues quickly.
Stay alert against online scams by avoiding suspicious links, unknown email attachments, and unverified requests for data. Additionally, protect all of your online accounts by creating strong, unique passwords for every service. Taking these basic security steps helps to reduce security risks and improve device protection.
Detailed information
File Search Path Control Flaw (CWE-427): This vulnerability may affect users who unknowingly download a specially crafted DLL file, place it in the same directory as the installer, and then run a prior version of the Kobo Desktop App installer.