Renderers can obtain access to random bluetooth device without permission in Electron
Modified: 11/8/2023
package
pkg:npm/electron
Renderers can obtain access to random bluetooth device without permission in Electron
Modified: 11/8/2023
libwebp: OOB write in BuildHuffmanTable
Modified: 9/10/2026
Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
Modified: 4/6/2026
Unpreventable top-level navigation
Modified: 7/8/2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Modified: 8/20/2026
Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
Modified: 4/6/2026
Chromium Remote Code Execution in electron
Modified: 11/8/2023
Electron: Use-after-free in offscreen child window paint callback
Modified: 4/6/2026
Context isolation bypass in Electron
Modified: 7/8/2026
Electron: shell.openPath path validation bypass via embedded null byte
Modified: 8/5/2026
Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
Modified: 4/6/2026
Electron vulnerable to URL spoofing via PDFium
Modified: 11/8/2023
Electron vulnerable to Heap Buffer Overflow in NativeImage
Modified: 7/1/2025
Context isolation bypass via Promise in Electron
Modified: 7/8/2026
AutoUpdater module fails to validate certain nested components of the bundle
Modified: 11/8/2023
Electron vulnerable to remote command execution
Modified: 11/8/2023
ASAR Integrity bypass via filetype confusion in electron
Modified: 9/10/2026
Electron vulnerable to out-of-package code execution when launched with arbitrary cwd
Modified: 9/10/2026
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
Modified: 4/6/2026
Electron: Use-after-free in offscreen shared texture release() callback
Modified: 4/6/2026
Electron Vulnerable to Code Execution by Re-Enabling Node.js Integration
Modified: 11/8/2023
Electron: USB device selection not validated against filtered device list
Modified: 4/6/2026
Heap buffer overflow in GPU
Modified: 11/8/2023
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
Modified: 8/20/2026
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
Modified: 8/5/2026
Electron: Use-after-free in download save dialog callback
Modified: 4/6/2026
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
Modified: 4/6/2026
Electron: DevTools embedder handler executes arbitrary files via shell open
Modified: 8/5/2026
Electron: Crash in clipboard.readImage() on malformed clipboard image data
Modified: 4/8/2026
Electron: Named window.open targets not scoped to the opener's browsing context
Modified: 4/8/2026
Arbitrary file read via window-open IPC in Electron
Modified: 7/8/2026
Electron: contextBridge object copy honors prototype setters
Modified: 8/5/2026
Electron protocol handler browser vulnerable to Command Injection
Modified: 11/8/2023
High severity vulnerability that affects electron
Modified: 11/8/2023
Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled
Modified: 11/8/2023
Electron: Context isolation bypass via Function.prototype.bind hijack
Modified: 8/5/2026
Context isolation bypass via contextBridge in Electron
Modified: 7/8/2026
Electron webPreferences vulnerability can be used to perform remote code execution
Modified: 11/8/2023
IPC messages delivered to the wrong frame in Electron
Modified: 9/10/2026
Electron: Context Isolation bypass via contextBridge VideoFrame transfer
Modified: 4/6/2026
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
Modified: 4/6/2026
Electron: Use-after-free in PowerMonitor on Windows and macOS
Modified: 4/6/2026
Electron: Parent process code-sign check is spoofable
Modified: 8/5/2026
Electron: Extension tab APIs operate across session boundaries
Modified: 8/5/2026
Context isolation bypass via leaked cross-context objects in Electron
Modified: 7/8/2026
Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API
Modified: 7/8/2026
Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled
Modified: 11/8/2023
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
Modified: 4/6/2026
Exfiltration of hashed SMB credentials on Windows via file:// redirect
Modified: 11/8/2023
Electron: Sandboxed iframes can launch external protocol handlers
Modified: 8/5/2026
Electron context isolation bypass via nested unserializable return value
Modified: 9/10/2026
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
Modified: 8/5/2026
Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow
Modified: 7/20/2026
Electron affected by libvpx's heap buffer overflow in vp8 encoding
Modified: 9/10/2026
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
Modified: 8/5/2026
Electron: Incorrect origin passed to permission request handler for iframe requests
Modified: 4/6/2026
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
Modified: 8/5/2026
Electron: HTTP redirect followed into local file loader
Modified: 8/5/2026
Electron: window.open features string controls some window options considered privileged
Modified: 8/5/2026
Electron has ASAR Integrity Bypass via resource modification
Modified: 9/5/2025
Remote Code Execution in electron
Modified: 11/8/2023
Electron: Cross-origin iframe can position native autofill popup
Modified: 8/5/2026
Electron: Service worker can spoof executeJavaScript IPC replies
Modified: 4/6/2026
electron ASAR Integrity bypass by just modifying the content
Modified: 7/1/2025
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
Modified: 4/6/2026