VDB
KO
MEDIUM 6.6

GHSA-m55f-7gqj-fr98

Electron: Extension tab APIs operate across session boundaries

Quick fix

GHSA-m55f-7gqj-fr98 — electron: upgrade to the fixed version with the command below.

npm install electron@39.8.8

Details

### Impact Extension tab and scripting APIs were not scoped to the extension's own `session`. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session.

Apps are only affected if they load Chrome extensions via `session.loadExtension` and rely on separate sessions to isolate that extension from other content. Apps that do not load extensions, or that use a single session, are not affected.

### Workarounds Only load extensions from sources you trust; do not rely on session separation alone to contain an extension.

### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8`

### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / electron
Introduced in: 0 Fixed in: 39.8.8
Fix npm install electron@39.8.8
npm / electron
Introduced in: 40.0.0-alpha.1 Fixed in: 40.9.0
Fix npm install electron@40.9.0
npm / electron
Introduced in: 41.0.0-alpha.1 Fixed in: 41.2.1
Fix npm install electron@41.2.1
npm / electron
Introduced in: 42.0.0-alpha.1 Fixed in: 42.0.0-beta.3
Fix npm install electron@42.0.0-beta.3

References