CVE-2017-16151: Code Injection
Affected versions of ElectronJS are susceptible to a remote code execution vulnerability that occurs when an affected application access remote content, even if the sandbox option is enabled.
Recommendation
Update to electron version 1.7.8 or later.
Other sources
Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the sandbox option is enabled.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-16151?
CVE-2017-16151 is a remote code execution vulnerability in Google Chromium that affects all recent versions of Electron.
How severe is CVE-2017-16151?
CVE-2017-16151 has a severity rating of 9.8, which is considered critical.
Which versions of Electron are affected by CVE-2017-16151?
Versions of Electron between 1.7.0 to 1.7.8, versions up to 1.6.14, and versions up to 1.7.8 with the Node.js platform are affected by CVE-2017-16151.
How can I fix CVE-2017-16151?
To fix CVE-2017-16151, update Electron to version 1.7.8 or later.
Where can I find more information about CVE-2017-16151?
You can find more information about CVE-2017-16151 on the NVD (National Vulnerability Database) website, ElectronJS blog, and GitHub.