Intel

AIKIDO-2024-10029

electron is vulnerable to Out-of-bounds Read

Out-of-bounds ReadCVE-2024-3157 Published Apr 16, 2024

60

Medium Risk

This Affects:

JSelectron
27.0.0 - 27.3.10
Fixed in 27.3.11
Are you affected? Scan for Free

TL;DR

Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)

Who does this affect?

You're affected if you are using a version which is within vulnerability ranges.

Background info

electron is vulnerable to Out-of-bounds Read in versions 27.0.0 - 27.3.10.

How to fix this

Upgrade electron library to patch version.