Junglewise Threat Intelligence

CVE-2023-44402: Electron ASAR integrity bypass via filetype confusion

CVE-2023-44402 · Severity: low · CVSS 3.1 · Published 2023-12-01

Vendors: OpenJS Foundation.

Executive brief

Electron is a framework used to build cross-platform desktop applications. A vulnerability in the ASAR integrity validation mechanism allows attackers with write access to the app installation directory to bypass security checks intended to prevent tampering with application code. This could enable malicious modification of application behavior or installation of malware on affected systems.

Technical details

The vulnerability is a cryptographic or integrity-check bypass (CWE-345) affecting Electron's embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses. The flaw exploits filetype confusion to circumvent ASAR file integrity checks. Attack requires the attacker to have local write access to the filesystem where the app is installed and also requires user interaction to trigger the vulnerability. The impact is limited to macOS where these fuses are currently supported. Patches are available in versions 22.3.24, 23.3.14, 24.8.3, 25.8.1, 26.2.1, and 27.0.0-alpha.7 or later.

Affected products

  • OpenJS Foundation Electron before 22.3.24; 23.0.0-alpha.1 to 23.3.13; 24.0.0-alpha.1 to 24.8.2; 25.0.0-alpha.1 to 25.8.0; 26.0.0-alpha.1 to 26.2.0; 27.0.0-alpha.1 to 27.0.0-alpha.6

Timeline

  • 2023-12-01: disclosed
  • 2023-12-01: patched

References