Junglewise Threat Intelligence

CVE-2020-15096: Electron context isolation bypass via Promise

CVE-2020-15096 · Severity: low · CVSS 3.1 · Published 2020-07-07

Executive brief

Electron is a framework used to build cross-platform desktop applications. A vulnerability in how Electron handles Promise operations allows code running in the renderer process to bypass context isolation and gain access to privileged Electron APIs. This could allow an attacker to perform unauthorized actions on the user's system if an application is exploited.

Technical details

This is a context isolation bypass vulnerability (CWE-501) caused by a bug in V8's Promise.then implementation. Code executing in the main world context of the renderer process can reach into the isolated Electron context and invoke privileged actions that should be restricted. The vulnerability affects Electron versions prior to 6.1.11, 7.x prior to 7.2.4, 8.x prior to 8.2.4, and 9.0.0-beta versions prior to beta.21. No user interaction or authentication is required; the attacker must control code in the renderer process (via malicious content, compromised website, or similar). There are no app-side workarounds; only updating Electron mitigates the issue.

Affected products

  • Electron Electron before 6.1.11, 7.0.0 before 7.2.4, 8.0.0 before 8.2.4, 9.0.0-beta.0 before 9.0.0-beta.21

Timeline

  • 2020-07-07: disclosed: GHSA-6vrv-94jv-crrg published
  • 2020-07-07: patched: Fixed in Electron 6.1.11, 7.2.4, 8.2.4, 9.0.0-beta.21

References