Junglewise Threat Intelligence

CVE-2021-39184: Electron sandboxed renderer information disclosure via nativeImage API

CVE-2021-39184 · Severity: low · CVSS 3.1 · Published 2021-10-12

Executive brief

Electron is a framework used to build cross-platform desktop applications. A vulnerability in the nativeImage API allows sandboxed renderers to request thumbnail images of arbitrary files on a user's system, potentially exposing sensitive data such as document contents, images, and other files. An attacker with code execution in a sandboxed renderer could exploit this to extract file contents without the user's knowledge.

Technical details

This vulnerability is an information disclosure flaw in Electron's nativeImage.createThumbnailFromPath API that fails to properly restrict access to files on the user's filesystem. A sandboxed renderer process can call this API to generate thumbnails of arbitrary files, which can reveal significant portions of file contents including text data. The attack requires code execution within a sandboxed renderer but does not require user interaction or elevated privileges. The vulnerability was fixed in Electron versions 11.5.0, 12.1.0, 13.3.0, 14.0.0, and 15.0.0-alpha.10. Mitigation is possible by enabling contextIsolation or by explicitly disabling the createThumbnailFromPath API.

Affected products

  • Electron Electron 10.1.0 to 11.4.x, 11.0.0-beta.1 to 11.4.x, 12.0.0-beta.1 to 12.0.x, 13.0.0-beta.1 to 13.2.x, 14.0.0-beta.1 before 14.0.0, 15.0.0-alpha.1 to 15.0.0-alpha.9

Timeline

  • 2021-10-12: disclosed
  • 2021-10-12: patched: Fixed in versions 11.5.0, 12.1.0, 13.3.0, 14.0.0, and 15.0.0-alpha.10

References