Intel

AIKIDO-2024-10083

electron is vulnerable to Type Confusion

Type ConfusionCVE-2024-4058 Published May 3, 2024

91

Critical Risk

This Affects:

JSelectron
29.0.0 - 29.3.1
Fixed in 29.3.2
Are you affected? Scan for Free

TL;DR

Type confusion in ANGLE in Google Chrome versions prior to 124.0.6367.78 allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Type Confusion in versions 29.0.0 - 29.3.1.

How to fix this

Upgrade the electron library to the patch version.