Executive brief
Electron is a framework for building cross-platform desktop applications. The framework's inter-process communication (IPC) system can incorrectly route messages intended for one embedded frame to a different frame in the same renderer process, potentially exposing sensitive data between different application contexts. This could allow a malicious embedded web page to intercept messages meant for another frame.
Technical details
The vulnerability is a message routing flaw in Electron's IPC system affecting frames when using out-of-process iframes (OOPIFs). An ID collision occurs when routing IPC messages sent via webContents.sendToFrame(), event.reply(), or the remote module from the main process to subframes. The vulnerability affects apps that use the remote module, call webContents.sendToFrame(), or call event.reply() in IPC handlers. No authentication or special privileges are required; a malicious frame could intercept messages through network access to the application. The fix addresses the ID collision by improving message routing logic and has been patched in Electron 9.4.0, 10.2.0, 11.1.0, and 12.0.0-beta.9 or later.
Affected products
- Electron Electron 0 through 9.3.5, 10.0.0 through 10.1.5, 11.0.0 through 11.0.5, 12.0.0-beta.0 through 12.0.0-beta.8, and all versions 8 and earlier
Timeline
- 2021-01-26: disclosed: Advisory published by Electron
- 2021-01-28: patched: Fixed in versions 9.4.0, 10.2.0, 11.1.0, and 12.0.0-beta.9