electron is vulnerable to Out-of-Bounds Read
65
Medium Risk
electron's embedded ANGLE Metal GPU path on macOS can compute incorrect pitch for compressed textures in pixel-buffer uploads. Crafted pages that drive compressed texture transfers can read beyond allocated buffers. Pre-fix versions may disclose sensitive GPU process memory. The backport corrects pitch computation for compressed texture PBO operations.
You are affected if you are using a version that falls within the vulnerable range and ship electron desktop apps on macOS.
electron is vulnerable to Out-of-Bounds Read in versions 40.0.0 - 40.10.2 and 41.0.0 - 41.7.1.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant