Intel

AIKIDO-2025-10543

electron is vulnerable to Use After Free

Use After FreeCVE-2025-8292 Published Aug 11, 2025

88

High Risk

This Affects:

JSelectron
35.0.0 - 37.2.5
Fixed in 37.2.6
Are you affected? Scan for Free

TL;DR

Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Use After Free in versions 35.0.0 - 37.2.5.

How to fix this

Upgrade the electron library to a patch version.