Intel

AIKIDO-2024-10015

electron is vulnerable to Type Confusion

Type ConfusionCVE-2024-2883 Published Apr 4, 2024

80

High Risk

This Affects:

JSelectron
27.0.0 - 27.3.8
Fixed in 27.3.9
28.0.0 - 28.2.9
Fixed in 28.2.10
29.0.0 - 29.1.6
Fixed in 29.2.0
Are you affected? Scan for Free

TL;DR

A use-after-free vulnerability in ANGLE in Google Chrome versions prior to 123.0.6312.86 allowed remote attackers to potentially exploit heap corruption via a specially crafted HTML page. (Chromium security severity: Critical)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Type Confusion in versions 29.0.0 - 29.1.6, 28.0.0 - 28.2.9 and 27.0.0 - 27.3.8.

How to fix this

Upgrade the electron library to a patch version.