electron is vulnerable to Use After Free
88
High Risk
electron's embedded Chromium XR runtime manager on Windows can leave a GPU observer registered after teardown. Crafted HTML that exercises WebXR paths can trigger use-after-free during runtime destruction. Pre-fix builds risk arbitrary code execution in the browser process. The backport removes the GPU observer in the XR runtime manager destructor.
You are affected if you are using a version that falls within the vulnerable range and ship electron desktop apps on Windows that expose WebXR content.
electron is vulnerable to Use After Free in versions 40.0.0 - 40.10.2 and 41.0.0 - 41.7.1.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant