Intel

AIKIDO-2024-10452

electron is vulnerable to Out-of-bounds Write

Out-of-bounds WriteCVE-2024-10827 Published Nov 19, 2024

88

High Risk

This Affects:

JSelectron
31.0.0 - 31.7.4
Fixed in 31.7.5
32.0.0 - 32.2.4
Fixed in 32.2.5
Are you affected? Scan for Free

TL;DR

A use-after-free vulnerability in the Serial component of Google Chrome prior to version 130.0.6723.116 allows a remote attacker to potentially exploit heap corruption by leveraging a crafted HTML page. (Chromium security severity: High)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Out-of-bounds Write in versions 31.0.0 - 31.7.4 and 32.0.0 - 32.2.4.

How to fix this

Upgrade the electron library to a patch version.