HIGH 7.7
GHSA-h9jc-284h-533g
Context isolation bypass via contextBridge in Electron
Details
### Impact Apps using both `contextIsolation` and `contextBridge` are affected.
This is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions.
### Workarounds There are no app-side workarounds, you must update your Electron version to be protected.
### Fixed Versions * `9.0.0-beta.21` * `8.2.4` * `7.2.4`
### For more information If you have any questions or comments about this advisory: * Email us at [security@electronjs.org](mailto:security@electronjs.org)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/electron/electron/security/advisories/GHSA-h9jc-284h-533g [WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-4077 [ADVISORY]
- https://github.com/electron/electron/commit/b8e347709245d2dc5640fbb3044d9b21b4eaa6b0 [WEB]
- https://www.electronjs.org/releases/stable?page=3#release-notes-for-v824 [WEB]