electron is vulnerable to Out-of-Bounds Read
43
Medium Risk
electron's embedded ANGLE Metal GPU path on macOS can read outside intended buffer bounds when sizing compressed texture uploads. Crafted HTML that drives GPU texture operations can reach the faulty pitch computation. Pre-fix builds may leak adjacent memory contents from the GPU process. The backport rounds buffer sizes safely for compressed texture PBO handling.
You are affected if you are using a version that falls within the vulnerable range and ship electron desktop apps on macOS.
electron is vulnerable to Out-of-Bounds Read in versions 40.0.0 - 40.10.2.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant