CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
19.7%
electron is vulnerable to Insufficient Verification of Data Authenticity. The vulnerability is due to the embeddedAsarIntegrityValidation
and onlyLoadAppFromAsar
fuses on MacOS systems. An attacker is able to inject malicious code or modify app behavior if they have write access to the .app
bundle filesystem.