CVE-2020-4077

Published
View on NVD ↗
CVSS v3
7.7
HIGH
CVSS v2
6.5
MEDIUM
Affected
1
PROJECT

Description

In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using both `contextIsolation` and `contextBridge` are affected. This is fixed in versions 9.0.0-beta.21, 8.2.4 and 7.2.4.

:electron: Build cross-platform desktop apps with JavaScript, HTML, and CSS
GitHubGitHub
122K