Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled are not impacted. This issue is fixed in versions 35.7.5, 36.8.1, 37.3.1 and 38.0.0-beta.6.
{
"cwe_ids": [
"CWE-829",
"CWE-94"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55305.json",
"cna_assigner": "GitHub_M"
}{
"extracted_events": [
{
"introduced": "36.0.0-alpha.1"
},
{
"fixed": "36.8.0"
},
{
"introduced": "37.0.0-alpha.1"
},
{
"fixed": "37.3.1"
},
{
"introduced": "38.0.0-alpha.1"
},
{
"fixed": "38.0.0-beta.6"
}
],
"source": [
"DESCRIPTION",
"REFERENCES"
]
}
"2026-08-12T15:16:44Z"
[
{
"id": "CVE-2025-55305-336a40a1",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"152494666416781242810517719231320519604",
"225621294261284233076206802270263648551",
"115705440781529763113046962627444993970",
"178111412695478762709679865612109648560",
"73911844454750564959446202323068893232",
"64816077172179537187033353531511817411",
"190079685644089414390125721502882456053",
"164275026456403570511986551124445333960",
"68083282541239337707222991128337435119",
"114137547968448916044453027153094341473",
"118177717049838624043161370458456721742",
"87335272485147941561134939866151684502",
"38125503356101783604380867880620683274",
"69703252615889611887930220466027851786",
"185625927738076278198987677630051462644",
"56534108699571538400922224531377193095",
"137426709248835087988570973629493043965",
"58389083308274755672287779275857279236",
"171193114796557878735715665164735886437",
"51419638149645591552157167443980661617",
"227302053439300061261615587786720510760",
"45601092781832770462638305846789432113",
"7510572762033959665471238074058011916",
"228184583599411597763315124517698770354"
]
},
"source": "https://github.com/electron/electron/commit/23a02934510fcf951428e14573d9b2d2a3c4f28b",
"target": {
"file": "shell/app/electron_main_delegate.cc"
}
},
{
"id": "CVE-2025-55305-7a090bbf",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"152494666416781242810517719231320519604",
"225621294261284233076206802270263648551",
"115705440781529763113046962627444993970",
"178111412695478762709679865612109648560",
"73911844454750564959446202323068893232",
"64816077172179537187033353531511817411",
"190079685644089414390125721502882456053",
"164275026456403570511986551124445333960",
"68083282541239337707222991128337435119",
"114137547968448916044453027153094341473",
"39518479210953554078288018750913182872",
"242982796452390228803972713655085831361",
"93936354092902648516486098748147714529",
"69703252615889611887930220466027851786",
"185625927738076278198987677630051462644",
"56534108699571538400922224531377193095",
"137426709248835087988570973629493043965",
"58389083308274755672287779275857279236",
"171193114796557878735715665164735886437",
"51419638149645591552157167443980661617",
"227302053439300061261615587786720510760",
"45601092781832770462638305846789432113",
"7510572762033959665471238074058011916",
"228184583599411597763315124517698770354"
]
},
"source": "https://github.com/electron/electron/commit/fdf29ce83870109d403f5c23ae529dbd0e8f4fee",
"target": {
"file": "shell/app/electron_main_delegate.cc"
}
},
{
"id": "CVE-2025-55305-b8eb7440",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"64816077172179537187033353531511817411",
"190079685644089414390125721502882456053",
"164275026456403570511986551124445333960",
"68083282541239337707222991128337435119",
"114137547968448916044453027153094341473",
"118177717049838624043161370458456721742",
"87335272485147941561134939866151684502",
"38125503356101783604380867880620683274",
"69703252615889611887930220466027851786",
"185625927738076278198987677630051462644",
"56534108699571538400922224531377193095",
"137426709248835087988570973629493043965",
"58389083308274755672287779275857279236",
"171193114796557878735715665164735886437",
"51419638149645591552157167443980661617",
"227302053439300061261615587786720510760",
"45601092781832770462638305846789432113",
"7510572762033959665471238074058011916",
"228184583599411597763315124517698770354"
]
},
"source": "https://github.com/electron/electron/commit/3f92511cdecc39f46b0e86cce40a0c691e301c9d",
"target": {
"file": "shell/app/electron_main_delegate.cc"
}
},
{
"id": "CVE-2025-55305-ed3d31ca",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"152494666416781242810517719231320519604",
"225621294261284233076206802270263648551",
"115705440781529763113046962627444993970",
"178111412695478762709679865612109648560",
"73911844454750564959446202323068893232",
"64816077172179537187033353531511817411",
"190079685644089414390125721502882456053",
"164275026456403570511986551124445333960",
"68083282541239337707222991128337435119",
"114137547968448916044453027153094341473",
"39518479210953554078288018750913182872",
"242982796452390228803972713655085831361",
"93936354092902648516486098748147714529",
"69703252615889611887930220466027851786",
"185625927738076278198987677630051462644",
"56534108699571538400922224531377193095",
"137426709248835087988570973629493043965",
"58389083308274755672287779275857279236",
"171193114796557878735715665164735886437",
"51419638149645591552157167443980661617",
"227302053439300061261615587786720510760",
"45601092781832770462638305846789432113",
"7510572762033959665471238074058011916",
"228184583599411597763315124517698770354"
]
},
"source": "https://github.com/electron/electron/commit/2e5a0b7220ebf955c6785cc5adb2e2b1cf77dac1",
"target": {
"file": "shell/app/electron_main_delegate.cc"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55305.json"