Intel

AIKIDO-2025-10189

electron is vulnerable to Sandbox Escape

Sandbox EscapeCVE-2025-2783 Published Mar 28, 2025

84

High Risk

This Affects:

JSelectron
33.0.0 - 33.4.7
Fixed in 33.4.8
34.0.0 - 34.4.0
Fixed in 34.4.1
35.0.0 - 35.1.1
Fixed in 35.1.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by an incorrect handle issue in Mojo in Google Chrome on Windows before 134.0.6998.177, where a remote attacker could exploit this vulnerability by tricking the sandbox validation when opening a malicious file, leading to a sandbox escape and potentially arbitrary code execution in the context of the host system. (Chromium security severity: High)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Sandbox Escape in versions 33.0.0 - 33.4.7, 34.0.0 - 34.4.0 and 35.0.0 - 35.1.1.

How to fix this

Upgrade the electron library to a patch version.