electron is vulnerable to Heap Corruption
88
High Risk
Embedded Chromium’s WebML implementation can hit integer sizing mistakes that lead to heap corruption when hostile HTML drives specific ML operator paths. Attackers use normal remote content delivery to steer execution into unsafe pooling or indirection logic. That opens high-impact memory corruption consistent with Chrome’s critical severity classification for the defect class. Electron consumes the correction through synchronized Chromium cherry-picks shipped on its maintenance lines.
You are affected if you are using a version that falls within the vulnerable range.
electron is vulnerable to Heap Corruption in versions 39.0.0 - 39.8.9.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant