Intel

AIKIDO-2025-10338

electron is vulnerable to Insufficient policy enforcement

Insufficient policy enforcementCVE-2025-4664 Published May 30, 2025

43

Medium Risk

This Affects:

JSelectron
34.0.0 - 34.5.6
Fixed in 34.5.7
35.0.0 - 35.4.0
Fixed in 35.5.0
Are you affected? Scan for Free

TL;DR

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Insufficient policy enforcement in versions 34.0.0 - 34.5.6 and 35.0.0 - 35.4.0.

How to fix this

Upgrade the electron library to the patch version.