Description
Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the [sandbox option](https://electron.atom.io/docs/api/sandbox-option) is enabled.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0225 | Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the [sandbox option](https://electron.atom.io/docs/api/sandbox-option) is enabled. |
Github GHSA |
GHSA-4w88-rjj3-x7wp | Chromium Remote Code Execution in electron |
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-16T16:54:03.710Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2017-16151
No data.
Status : Modified
Published: 2018-06-07T02:29:04.487
Modified: 2024-11-21T03:15:55.420
Link: CVE-2017-16151
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA