Apps using contextIsolation
are affected.
This is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions.
There are no app-side workarounds, you must update your Electron version to be protected.
9.0.0-beta.21
8.2.4
7.2.4
9.0.0-beta.*
If you have any questions or comments about this advisory: * Email us at security@electronjs.org
{ "github_reviewed": true, "cwe_ids": [ "CWE-501" ], "severity": "HIGH", "github_reviewed_at": "2020-07-06T23:55:29Z", "nvd_published_at": null }