Intel

AIKIDO-2025-10173

electron is vulnerable to Type Confusion

Type ConfusionCVE-2025-1920 Published Mar 21, 2025

88

High Risk

This Affects:

JSelectron
33.0.0 - 33.4.5
Fixed in 33.4.6
34.0.0 - 34.3.3
Fixed in 34.3.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a Type Confusion issue in Google Chrome prior to 134.0.6998.88. A remote attacker can exploit this vulnerability by crafting a malicious HTML page, potentially leading to heap corruption and arbitrary code execution. (Chromium security severity: High)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Type Confusion in versions 33.0.0 - 33.4.5 and 34.0.0 - 34.3.3.

How to fix this

Upgrade the electron library to a patch version.