electron is vulnerable to Heap-based Buffer Overflow
88
High Risk
electron's bundled WebRTC audio path can overflow heap buffers when crossfading from comfort-noise or expand frames to normal frames with mismatched vector sizes. Crafted HTML that drives WebRTC audio streams can supply inconsistent frame sizes. Pre-fix builds risk sandboxed memory corruption and code execution. The backport validates vector sizes before performing the crossfade.
You are affected if you are using a version that falls within the vulnerable range.
electron is vulnerable to Heap-based Buffer Overflow in versions 40.0.0 - 40.10.2.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant