Electron App Vulnerable to Recode Code Execution Vulnerability

By

Major applications like Skype, Slack, and Signal are affected by the flaw.

Electron, an open source web application platform for creating cross-platform applications, has reported a critical vulnerability that affects Windows users. The remote code execution vulnerability affects several popular apps, including Skype, Slack, and Signal.

A remote code execution vulnerability has been discovered, affecting Electron apps that use custom protocol handlers. This vulnerability has been assigned the CVE identifier CVE-2018-1000006,” wrote Electron in a blog post.

The vulnerability affects every Electron app that runs on Windows and registers as the default handler for a protocol, like myapp://.

According to Electron, “Such apps can be affected regardless of how the protocol is registered, e.g. using native code, the Windows registry, or Electron’s app.setAsDefaultProtocolClient API.”

Electron has released a new version of the framework that fixes the vulnerability. If you work on Windows and are using Electron to build your apps, please update to the latest version immediately. Linux and MacOS users are not affected by the vulnerability.

01/31/2018

Related content

comments powered by Disqus
Subscribe to our ADMIN Newsletters
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs



Support Our Work

ADMIN content is made possible with support from readers like you. Please consider contributing when you've found an article to be beneficial.

Learn More”>
	</a>

<hr>		    
			</div>
		    		</div>

		<div class=