electron is vulnerable to Use After Free
88
High Risk
electron's bundled WebRTC video encoder adapters can be destroyed while encoders remain initialized. Crafted pages that start and tear down WebRTC capture sessions can hit the use-after-free during encoder teardown. Pre-fix versions risk arbitrary code execution through crafted HTML. The backport releases video encoders before destruction and in simulcast adapter destructors.
You are affected if you are using a version that falls within the vulnerable range.
electron is vulnerable to Use After Free in versions 40.0.0 - 40.10.2 and 41.0.0 - 41.7.1.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant