Image Credits:Artystarty / Getty Images

Exploit puts popular web and mobile apps at risk

A new exploit could allow users to bypass security checks in Electron, a popular cross-platform development framework. The exploit, posted by Trustwave, has been patched and developers should update their apps as soon as possible.

The exploit could allow cross site scripting in some apps by turning on nodeIntegration, a method that allows the app to not only connect to its own modules but also Node.js modules.

From the announcement:

Electron applications are essentially web apps, which means they’re susceptible to cross-site scripting attacks through failure to correctly sanitize user-supplied input. A default Electron application includes access to not only its own APIs, but also includes access to all of Node.js’ built in modules. This makes XSS particularly dangerous, as an attacker’s payload can allow do some nasty things such as require in the child_process module and execute system commands on the client-side. Atom had an XSS vulnerability not too long ago which did exactly that. You can remove access to Node.js by passing nodeIntegration: false into your application’s webPreferences.

Many popular apps use Electron including Discord, Signal, Visual Studio Code, and Github. Slack also uses Electron for its apps.

The exploit depends on the nodeIntegration setting and the process of opening a new window. While in most cases nodeIntegration is set to false, in some cases you can set nodeIntegration to true and then pass other nefarious scripts including calling the child_process module which lets you make system calls like spawn which then lets you run commands in the operating system.

You can see Electron’s website here and here is their blog post on the update. Most apps shouldn’t be effected as long as you’ve upgraded the platform in the last few weeks.

Techcrunch event

Disrupt 2026: The tech ecosystem, all in one room

Your next round. Your next hire. Your next breakout opportunity. Find it at TechCrunch Disrupt 2026, where 10,000+ founders, investors, and tech leaders gather for three days of 250+ tactical sessions, powerful introductions, and market-defining innovation. Register now to save up to $400.

Save up to $300 or 30% to TechCrunch Founder Summit

1,000+ founders and investors come together at TechCrunch Founder Summit 2026 for a full day focused on growth, execution, and real-world scaling. Learn from founders and investors who have shaped the industry. Connect with peers navigating similar growth stages. Walk away with tactics you can apply immediately

Offer ends March 13.

San Francisco, CA | October 13-15, 2026

Topics

, , , , , , , ,
Loading the next article
Error loading the next article