Intel

AIKIDO-2024-10435

electron is vulnerable to Out-of-bounds Write

Out-of-bounds WriteCVE-2024-10487 Published Nov 8, 2024

98

Critical Risk

This Affects:

JSelectron
31.0.0 - 31.7.3
Fixed in 31.7.4
32.0.0 - 32.2.2
Fixed in 32.2.3
Are you affected? Scan for Free

TL;DR

Out-of-bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allows a remote attacker to perform out-of-bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Out-of-bounds Write in versions 31.0.0 - 31.7.3 and 32.0.0 - 32.2.2.

How to fix this

Upgrade the electron library to a patch version.