Intel

AIKIDO-2025-10021

electron is vulnerable to Type Confusion

Type ConfusionCVE-2024-12053 Published Jan 15, 2025

88

High Risk

This Affects:

JSelectron
31.0.0 - 31.7.6
Fixed in 31.7.7
32.0.0 - 32.2.7
Fixed in 32.2.8
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by a Type Confusion vulnerability in Chrome's V8 engine prior to version 131.0.6778.108. This vulnerability allows attackers to exploit object corruption through a specially crafted HTML page. By creating a malicious HTML page, attackers can execute arbitrary code or bypass object-level validation, potentially compromising user systems.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Type Confusion in versions 32.0.0 - 32.2.7 and 31.0.0 - 31.7.6.

How to fix this

Upgrade the electron library to the patch version.