A security researcher discovered a vulnerability in ToDesktop, an Electron app bundler service, which allowed for remote code execution on hundreds of millions of users of popular apps such as Clickup, Cursor, and Notion Calendar. The vulnerability was caused by an insecure collection in ToDesktop's Firebase database and a post-install script in the package.json file. The researcher reported the issue to ToDesktop, which quickly fixed the vulnerability and compensated the researcher. The incident highlights the importance of security practices and responsible disclosure.