electron is vulnerable to Type Confusion
75
High Risk
electron's embedded Chromium media GPU path on Linux can confuse plane types when constructing native pixmap planes from renderer-controlled video input. A compromised renderer feeding crafted video can reach the type-confused construction logic. Pre-fix versions risk sandbox escape through malformed plane metadata. The backport enforces safe numeric ranges for native pixmap plane construction.
You are affected if you are using a version that falls within the vulnerable range and ship electron desktop apps on Linux.
electron is vulnerable to Type Confusion in versions 40.0.0 - 40.10.2 and 41.0.0 - 41.7.1.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant