Intel

AIKIDO-2025-10340

electron is vulnerable to Insufficient policy enforcement

Insufficient policy enforcementCVE-2025-4609 Published May 30, 2025

65

Medium Risk

This Affects:

JSelectron
34.0.0 - 34.5.6
Fixed in 34.5.7
35.0.0 - 35.4.0
Fixed in 35.5.0
Are you affected? Scan for Free

TL;DR

This vulnerability in Chromium's Mojo inter-process communication (IPC) system could allow an untrusted process to leak handles by reflecting a broker-initiated transport back to the broker. If an attacker-controlled (untrusted) node receives a transport from a broker (a privileged process managing handle sharing), it could maliciously reflect it back. When the broker later deserializes another transport containing handles using the reflected transport, handle leaks occur—potentially exposing sensitive resources or enabling privilege escalation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Insufficient policy enforcement in versions 34.0.0 - 34.5.6 and 35.0.0 - 35.4.0.

How to fix this

Upgrade the electron library to the patch version.