A High severity vulnerability has been discovered in Chrome which affects all software based on Chromium, including Electron.
CVE-2019-5786。 You can read more about it in the Chrome Blog Post.
Please note that Chrome has reports of this vulnerability being used in the wild so it is strongly recommended you upgrade Electron ASAP.
Affected apps should upgrade to a patched version of Electron.
We've published new versions of Electron which include fixes for this vulnerability:
The latest beta of Electron 5 was tracking Chromium 73 and therefore is already patched:
This vulnerability was discovered by Clement Lecigne of Google's Threat Analysis Group and reported to the Chrome team. The Chrome blog post can be found here.
要了解更多关于维护您的 Electron 应用安全的最佳做法，请参阅我们的 安全教程。
If you wish to report a vulnerability in Electron, email firstname.lastname@example.org.