Intel

AIKIDO-2025-10523

electron is vulnerable to Use After Free

Use After FreeCVE-2025-7657 Published Aug 3, 2025

88

High Risk

This Affects:

JSelectron
35.0.0 - 37.2.3
Fixed in 37.2.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by use after free in WebRTC in Google Chrome prior to 138.0.7204.157 and allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High).

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Use After Free in versions 35.0.0 - 37.2.3.

How to fix this

Upgrade the electron library to a patch version.