Intel

AIKIDO-2024-10222

electron is vulnerable to Use-After-Free

Use-After-FreeCVE-2024-6991 Published Aug 15, 2024

80

High Risk

This Affects:

JSelectron
29.0.0 - 29.4.5
Fixed in 29.4.6
30.0.0 - 30.3.1
Fixed in 30.4.0
31.0.0 - 31.3.1
Fixed in 31.4.0
Are you affected? Scan for Free

TL;DR

A use-after-free vulnerability in Dawn in Google Chrome prior to 127.0.6533.72 allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Use-After-Free in versions 29.0.0 - 29.4.5, 30.0.0 - 30.3.1 and 31.0.0 - 31.3.1.

How to fix this

Upgrade the electron library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform