Intel

AIKIDO-2024-10100

electron is vulnerable to Use-After-Free

Use-After-FreeCVE-2024-4948 Published May 23, 2024

75

High Risk

This Affects:

JSelectron
28.0.0 - 28.3.1
Fixed in 28.3.2
29.0.0 - 29.4.0
Fixed in 29.4.1
Are you affected? Scan for Free

TL;DR

A use-after-free vulnerability in Dawn in Google Chrome prior to 125.0.6422.60 allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Use-After-Free in versions 28.0.0 - 28.3.1 and 29.0.0 - 29.4.0.

How to fix this

Upgrade the electron library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform