PageSourceSearch

https://www.electronjs.org/assets/js/193f3fe8.66d74f24.js

js electronjs.org collected 2026-09-24 07:04:34 UTC 5,095 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkelectronjs=self.webpackChunkelectronjs||[]).push([["27471"],{91717(e,t,r){r.r(t),r.d(t,{assets:()=>a,contentTitle:()=>s,default:()=>u,frontMatter:()=>o,metadata:()=>n,toc:()=>c});var n=r(22959),i=r(74848),l=r(28453);let o={title:"Chromium FileReader Vulnerability Fix",date:new Date("2019-03-07T00:00:00.000Z"),authors:"MarshallOfSound",slug:"filereader-fix",tags:["security"]},s,a={authorsImageUrls:[void 0]},c=[{value:"Scope",id:"scope",level:2},{value:"Mitigation",id:"mitigation",level:2},{value:"Further Information",id:"further-information",level:2}];function h(e){let t={a:"a",code:"code",h2:"h2",hr:"hr",li:"li",p:"p",ul:"ul",...(0,l.R)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(t.p,{children:"A High severity vulnerability has been discovered in Chrome which affects all software based on Chromium, including Electron."}),"\n",(0,i.jsxs)(t.p,{children:["This vulnerability has been assigned ",(0,i.jsx)(t.code,{children:"CVE-2019-5786"}),". You can read more about it in the ",(0,i.jsx)(t.a,{href:"https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html",children:"Chrome Blog Post"}),"."]}),"\n",(0,i.jsx)(t.p,{children:"Please note that Chrome has reports of this vulnerability being used in the wild so it is strongly recommended you upgrade Electron ASAP."}),"\n",(0,i.jsx)(t.hr,{}),"\n",(0,i.jsx)(t.h2,{id:"scope",children:"Scope"}),"\n",(0,i.jsx)(t.p,{children:"This affects any Electron application that may run third-party or untrusted JavaScript."}),"\n",(0,i.jsx)(t.h2,{id:"mitigation",children:"Mitigation"}),"\n",(0,i.jsx)(t.p,{children:"Affected apps should upgrade to a patched version of Electron."}),"\n",(0,i.jsx)(t.p,{children:"We've published new versions of Electron which include fixes for this vulnerability:"}),"\n",(0,i.jsxs)(t.ul,{children:["\n",(0,i.jsx)(t.li,{children:(0,i.jsx)(t.a,{href:"https://github.com/electron/electron/releases/tag/v4.0.8",children:"4.0.8"})}),"\n",(0,i.jsx)(t.li,{children:(0,i.jsx)(t.a,{href:"https://github.com/electron/electron/releases/tag/v3.1.6",children:"3.1.6"})}),"\n",(0,i.jsx)(t.li,{children:(0,i.jsx)(t.a,{href:"https://github.com/electron/electron/releases/tag/v3.0.16",children:"3.0.16"})}),"\n",(0,i.jsx)(t.li,{children:(0,i.jsx)(t.a,{href:"https://github.com/electron/electron/releases/tag/v2.0.18",children:"2.0.18"})}),"\n"]}),"\n",(0,i.jsx)(t.p,{children:"The latest beta of Electron 5 was tracking Chromium 73 and therefore is already patched:"}),"\n",(0,i.jsxs)(t.ul,{children:["\n",(0,i.jsx)(t.li,{children:(0,i.jsx)(t.a,{href:"https://github.com/electron/electron/releases/tag/v5.0.0-beta.5",children:"5.0.0-beta.5"})}),"\n"]}),"\n",(0,i.jsx)(t.h2,{id:"further-information",children:"Further Information"}),"\n",(0,i.jsxs)(t.p,{children:["This vulnerability was discovered by Clement Lecigne of Google's Threat Analysis Group and reported to the Chrome team. The Chrome blog post can be found ",(0,i.jsx)(t.a,{href:"https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html",children:"here"}),"."]}),"\n",(0,i.jsxs)(t.p,{children:["To learn more about best practices for keeping your Electron apps secure, see our ",(0,i.jsx)(t.a,{href:"https://electronjs.org/docs/tutorial/security",children:"security tutorial"}),"."]}),"\n",(0,i.jsxs)(t.p,{children:["Please file a ",(0,i.jsx)(t.a,{href:"https://github.com/electron/electron/security",children:"GitHub Security Advisory"})," if you wish to report a vulnerability\nin Electron."]})]})}function u(e={}){let{wrapper:t}={...(0,l.R)(),...e.components};return t?(0,i.jsx)(t,{...e,children:(0,i.jsx)(h,{...e})}):h(e)}},28453(e,t,r){r.d(t,{R:()=>o,x:()=>s});var n=r(96540);let i={},l=n.createContext(i);function o(e){let t=n.useContext(l);return n.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function s(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:o(e.components),n.createElement(l.Provider,{value:t},e.children)}},22959(e){e.exports=JSON.parse('{"permalink":"/blog/filereader-fix","source":"@site/blog/filereader-fix.md","title":"Chromium FileReader Vulnerability Fix","description":"A High severity vulnerability has been discovered in Chrome which affects all software based on Chromium, including Electron.","date":"2019-03-07T00:00:00.000Z","tags":[{"inline":false,"label":"Security","permalink":"/blog/tags/security","de
1scription":"Blog posts related to security"}],"readingTime":1.24,"hasTruncateMarker":false,"authors":[{"name":"MarshallOfSound","url":"https://github.com/MarshallOfSound","imageURL":"https://github.com/MarshallOfSound.png?size=96","key":"MarshallOfSound","page":null}],"frontMatter":{"title":"Chromium FileReader Vulnerability Fix","date":"2019-03-07T00:00:00.000Z","authors":"MarshallOfSound","slug":"filereader-fix","tags":["security"]},"unlisted":false,"prevItem":{"title":"Electron Governance","permalink":"/blog/governance"},"nextItem":{"title":"Discontinuing support for 32-bit Linux","permalink":"/blog/linux-32bit-support"}}')}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.