electron is vulnerable to Use After Free
88
High Risk
electron's bundled WebRTC Pipewire cursor path on Linux contains a race around shared cursor data. Crafted page content that drives WebRTC capture can reach the faulty lifetime handling. Pre-fix builds can hit use-after-free memory corruption in the media stack. The backport serializes access to the Pipewire cursor data to remove the race.
You are affected if you are using a version that falls within the vulnerable range and ship electron desktop apps on Linux.
electron is vulnerable to Use After Free in versions 40.0.0 - 40.10.2 and 41.0.0 - 41.7.1.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant