electron is vulnerable to Memory Corruption
88
High Risk
Electron bundles Chromium-family components that received upstream memory-safety and validation backports across media, GPU, UI, accessibility, Skia, ANGLE, and rendering paths. Crafted web or renderer-controlled content can reach use-after-free, heap overflow, integer overflow, and validation defects in those components. Pre-fix applications can expose users to crashes or memory corruption with potential process compromise through embedded Chromium functionality. The fix backports the upstream Chromium, ANGLE, and Skia patches into Electron's bundled dependencies.
You are affected if you are using a version that falls within the vulnerable range.
electron is vulnerable to Memory Corruption in versions 40.0.0 - 40.10.0, 41.0.0 - 41.6.1 and 42.0.0 - 42.1.0.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant