Intel

AIKIDO-2024-10222

electron is vulnerable to Use-After-Free

Use-After-FreeCVE-2024-6991 Published Aug 15, 2024

80

High Risk

This Affects:

JSelectron
29.0.0 - 29.4.5
Fixed in 29.4.6
30.0.0 - 30.3.1
Fixed in 30.4.0
31.0.0 - 31.3.1
Fixed in 31.4.0
Are you affected? Scan for Free

TL;DR

A use-after-free vulnerability in Dawn in Google Chrome prior to 127.0.6533.72 allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Use-After-Free in versions 29.0.0 - 29.4.5, 30.0.0 - 30.3.1 and 31.0.0 - 31.3.1.

How to fix this

Upgrade the electron library to the patch version.