Intel

AIKIDO-2024-10188

electron is vulnerable to Use-After-Free

Use-After-FreeCVE-2024-6291

75

High Risk

This Affects:

JSelectron
29.0.0 - 29.4.4
Fixed in 29.4.5

TL;DR

Use-after-free in Swiftshader in Google Chrome prior to 126.0.6478.126 allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Use-After-Free in versions 29.0.0 - 29.4.4.

How to fix this

Upgrade the electron library to the patch version.