electron is vulnerable to Use After Free
88
High Risk
electron's embedded ANGLE GPU stack on Windows can free GPU resources while D3D11 transform-feedback state still references them. Remote pages that exercise GPU code paths can trigger the use-after-free. Pre-fix versions risk sandboxed arbitrary code execution through crafted HTML. The backport corrects buffer state tracking in transform feedback.
You are affected if you are using a version that falls within the vulnerable range and ship electron desktop apps on Windows.
electron is vulnerable to Use After Free in versions 40.0.0 - 40.10.2.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant