Intel

AIKIDO-2024-10346

electron is vulnerable to Type Confusion

Type ConfusionCVE-2024-9602

88

High Risk

This Affects:

JSelectron
31.0.0 - 31.7.0
Fixed in 31.7.1
32.0.0 - 32.2.0
Fixed in 32.2.1

TL;DR

Type confusion in V8 in Google Chrome prior to version 129.0.6668.100 allowed remote attackers to perform an out-of-bounds memory write via a crafted HTML page. (Chromium security severity: High)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Type Confusion in versions 31.0.0 - 31.7.0 and 32.0.0 - 32.2.0.

How to fix this

Upgrade the electron library to a patch version.