Intel

AIKIDO-2025-10021

electron is vulnerable to Type Confusion

Type ConfusionCVE-2024-12053 Published Jan 15, 2025

88

High Risk

This Affects:

JSelectron
31.0.0 - 31.7.6
Fixed in 31.7.7
32.0.0 - 32.2.7
Fixed in 32.2.8
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by a Type Confusion vulnerability in Chrome's V8 engine prior to version 131.0.6778.108. This vulnerability allows attackers to exploit object corruption through a specially crafted HTML page. By creating a malicious HTML page, attackers can execute arbitrary code or bypass object-level validation, potentially compromising user systems.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Type Confusion in versions 32.0.0 - 32.2.7 and 31.0.0 - 31.7.6.

How to fix this

Upgrade the electron library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform