Junglewise Threat Intelligence

CVE-2025-55305: Electron ASAR integrity bypass via resource modification

CVE-2025-55305 · Severity: low · CVSS 3.1 · Published 2025-09-03

Executive brief

Electron is a framework used to build desktop applications with web technologies. This vulnerability allows an attacker with local write access to an application's installation directory to bypass security validation and inject malicious code into the application, but only if the developer has explicitly enabled integrity checking fuses. The risk is limited to Windows systems and requires the attacker to already have write access to the protected resources folder.

Technical details

This vulnerability (CWE-94: Code Injection, CWE-829: Untrusted Control Sphere) is an ASAR integrity validation bypass that affects Electron applications with both embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. The vulnerability allows an attacker with local filesystem write access to the resources folder on Windows to modify ASAR archive contents and execute arbitrary code. The attack requires local privileges, low attack complexity, and user interaction to trigger the vulnerable code path. The vulnerability has been patched in versions 35.7.5, 36.8.1, 37.3.1, and 38.0.0-beta.6 and later.

Affected products

  • Electron Electron all versions before 35.7.5; 36.0.0-alpha.1 to before 36.8.1; 37.0.0-alpha.1 to before 37.3.1; 38.0.0-alpha.1 to before 38.0.0-beta.6

Timeline

  • 2025-09-03: disclosed
  • 2025-09-03: patched: Fixed in versions 35.7.5, 36.8.1, 37.3.1, 38.0.0-beta.6

References