Intel

AIKIDO-2024-10100

electron is vulnerable to Use-After-Free

Use-After-FreeCVE-2024-4948 Published May 23, 2024

75

High Risk

This Affects:

JSelectron
28.0.0 - 28.3.1
Fixed in 28.3.2
29.0.0 - 29.4.0
Fixed in 29.4.1
Are you affected? Scan for Free

TL;DR

A use-after-free vulnerability in Dawn in Google Chrome prior to 125.0.6422.60 allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Use-After-Free in versions 28.0.0 - 28.3.1 and 29.0.0 - 29.4.0.

How to fix this

Upgrade the electron library to the patch version.