Intel

AIKIDO-2025-10438

electron is vulnerable to ASAR Integrity Bypass By Just Modifying The Content

ASAR Integrity Bypass By Just Modifying The ContentCVE-2024-46992 Published Jul 7, 2025

78

High Risk

This Affects:

JSelectron
30.0.1 - 30.0.4
Fixed in 30.0.5
Are you affected? Scan for Free

TL;DR

Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 30.0.0-alpha.1 to before 30.0.5 and 31.0.0-alpha.1 to before 31.0.0-beta.1, Electron is vulnerable to an ASAR Integrity bypass.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and the application must be launched from a writable filesystem on Windows when the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses are enabled.

Background info

electron is vulnerable to ASAR Integrity Bypass By Just Modifying The Content in versions 30.0.1 - 30.0.4.

How to fix this

Upgrade the electron library to the patch version.