electron is vulnerable to User Interface (UI) Misrepresentation of Critical Information
42
Medium Risk
electron's embedded Chromium UI layer on Windows can mis-handle drag state tracking when a renderer is already compromised. A crafted HTML page can influence UI presentation and enable spoofing of trusted interface elements. Before the fix, users could be misled by attacker-controlled UI overlays. The backport tracks in-progress drags with static state to close the inappropriate implementation path.
You are affected if you are using a version that falls within the vulnerable range and ship electron desktop apps on Windows.
electron is vulnerable to User Interface (UI) Misrepresentation of Critical Information in versions 40.0.0 - 40.10.2 and 41.0.0 - 41.7.1.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant