Intel

AIKIDO-2024-10176

electron is vulnerable to Type Confusion

Type ConfusionCVE-2024-6100 Published Jul 12, 2024

85

High Risk

This Affects:

JSelectron
29.0.0 - 29.4.2
Fixed in 29.4.3
30.0.0 - 30.1.2
Fixed in 30.2.0
Are you affected? Scan for Free

TL;DR

Type confusion in V8 in Google Chrome prior to 126.0.6478 allows a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High). This issue is fixed along with other security improvements.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Type Confusion in versions 29.0.0 - 29.4.2 and 30.0.0 - 30.1.2.

How to fix this

Upgrade the electron library to the patch version.