Executive brief
Electron is a framework used to build cross-platform desktop applications. On Windows, applications built with Electron that register as protocol handlers (such as myapp://) are vulnerable to remote code execution when a user clicks a malicious link. An attacker can exploit this to execute arbitrary code with the privileges of the Electron application, potentially compromising user data and system security.
Technical details
The vulnerability is a command injection flaw (CWE-78) in Electron's protocol handler implementation on Windows. When Electron applications register as default protocol handlers via app.setAsDefaultProtocolClient(), the framework fails to properly sanitize additional command-line arguments passed to Chromium. An attacker can craft a malicious URI (e.g., myapp://--flag=value) that injects arbitrary Chromium command-line switches when the link is clicked by a user. This requires user interaction (clicking a link) and affects only Windows systems; macOS and Linux are unaffected. Patches are available in versions 1.6.17, 1.7.12, and 1.8.2-beta.5 or later. As a workaround, developers can append "--" to prevent further option parsing.
Affected products
- Electron Electron 1.6.0 to 1.6.16, 1.7.0 to 1.7.11, 1.8.0 to 1.8.2-beta.3
Timeline
- 2018-01-23: disclosed: Vulnerability advisory published
- 2018-01: patched: Patches released: 1.6.17, 1.7.12, 1.8.2-beta.5