Description
In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using both `contextIsolation` and `contextBridge` are affected. This is fixed in versions 9.0.0-beta.21, 8.2.4 and 7.2.4.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_confirm
https://github.com/electron/electron/security/advisories/GHSA-h9jc-284h-533g
Release Notes, Vendor Advisory x_refsource_misc
https://www.electronjs.org/releases/stable?page=3#release-notes-for-v824
Scores
CVSS v3
7.7
EPSS
0.0100
EPSS Percentile
59.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Details
CWE
CWE-501
Status
published
Products (3)
electronjs/electron
9.0.0 (21 CPE variants)
electronjs/electron
7.0.0 - 7.2.4
npm/electron
0 - 7.2.4npm
Published
Jul 07, 2020
Tracked Since
Feb 18, 2026