Intel

AIKIDO-2025-10350

electron is vulnerable to Out-of-bounds Read

Out-of-bounds ReadCVE-2025-5419 Published Jun 6, 2025

88

High Risk

This Affects:

JSelectron
34.0.0 - 34.5.7
Fixed in 34.5.8
35.0.0 - 35.5.0
Fixed in 35.5.1
36.0.0 - 36.3.2
Fixed in 36.4.0
Are you affected? Scan for Free

TL;DR

Out-of-bounds read and write vulnerabilities in V8 in Google Chrome prior to version 137.0.7151.68 allow remote attackers to potentially exploit heap corruption by tricking users into opening a specially crafted HTML page. This issue could lead to arbitrary code execution and is rated as High severity by the Chromium security team.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Out-of-bounds Read in versions 34.0.0 - 34.5.7, 35.0.0 - 35.5.0 and 36.0.0 - 36.3.2.

How to fix this

Upgrade the electron library to the patch version.