electron is vulnerable to Use After Free
88
High Risk
electron's embedded Chromium QUIC networking stack can use QUIC proxy socket memory after it is freed when handling malicious network traffic. Remote attackers can reach the faulty datagram client socket lifetime through QUIC-enabled connections. Pre-fix builds risk sandboxed code execution from network input. The backport adds advanced memory-safety checks on the vulnerable QUIC class as shipped upstream on Chrome stable.
You are affected if you are using a version that falls within the vulnerable range.
electron is vulnerable to Use After Free in versions 40.0.0 - 40.10.2 and 41.0.0 - 41.7.1.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant