Intel

AIKIDO-2025-10130

electron is vulnerable to Out-of-bounds Read

Out-of-bounds ReadCVE-2025-0998 Published Mar 4, 2025

59

Medium Risk

This Affects:

JSelectron
32.0.0 - 32.3.2
Fixed in 32.3.3
33.0.0 - 33.4.2
Fixed in 33.4.3
Are you affected? Scan for Free

TL;DR

An out-of-bounds memory access vulnerability in V8 in Google Chrome before version 133.0.6943.98 allows a remote attacker to execute arbitrary code within the browser's sandbox by tricking a user into opening a specially crafted HTML page. (Chromium security severity: High)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Out-of-bounds Read in versions 32.0.0 - 32.3.2 and 33.0.0 - 33.4.2.

How to fix this

Upgrade the electron library to a patch version.