Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.Test your applications
- Snyk ID SNYK-JS-ELECTRON-1252280
- published 22 Apr 2021
- disclosed 20 Apr 2021
- credit Bohan Liu of Tencent Security Xuanwu Lab, Moon Liang of Tencent Security Xuanwu Lab
How to fix?
electron to version 12.0.5, 11.4.4, 10.4.4 or higher.
Affected versions of this package are vulnerable to Use After Free via Chrome which allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.