Junglewise Threat Intelligence

CVE-2018-1000006: Electron remote code execution via protocol handler

CVE-2018-1000006 · Severity: low · CVSS 3 · Published 2018-01-23

Executive brief

Electron is a framework used to build cross-platform desktop applications. On Windows, applications built with Electron that register as protocol handlers (such as myapp://) are vulnerable to remote code execution when a user clicks a malicious link. An attacker can exploit this to execute arbitrary code with the privileges of the Electron application, potentially compromising user data and system security.

Technical details

The vulnerability is a command injection flaw (CWE-78) in Electron's protocol handler implementation on Windows. When Electron applications register as default protocol handlers via app.setAsDefaultProtocolClient(), the framework fails to properly sanitize additional command-line arguments passed to Chromium. An attacker can craft a malicious URI (e.g., myapp://--flag=value) that injects arbitrary Chromium command-line switches when the link is clicked by a user. This requires user interaction (clicking a link) and affects only Windows systems; macOS and Linux are unaffected. Patches are available in versions 1.6.17, 1.7.12, and 1.8.2-beta.5 or later. As a workaround, developers can append "--" to prevent further option parsing.

Affected products

  • Electron Electron 1.6.0 to 1.6.16, 1.7.0 to 1.7.11, 1.8.0 to 1.8.2-beta.3

Timeline

  • 2018-01-23: disclosed: Vulnerability advisory published
  • 2018-01: patched: Patches released: 1.6.17, 1.7.12, 1.8.2-beta.5

References