Popular web app framework allows remote code execution

By

Slack, Skype, Signal, Node JS Package Manager, Shopify affected.

A serious vulnerability in the Electron framework, which underpins many web apps such as Slack, Skype and Signal, could be exploited to allow attackers to run malicious code on victim computers.

Popular web app framework allows remote code execution

The vulnerability affects Electron.js apps running on Windows. Apps on Apple's macOS operating system or Linux distributions are not impacted.

Electron has patched the remote code execution vulnerability in the latest versions of the framework, and is urging developers to update their applications.

Attackers can take advantage of the flaw by abusing Electron apps that register themselves as the default handler for a protocol, such as slack://.

This means users who click on specially crafted links could inadvertently run malicious code that can be used for information leakage as well as to deploy ransomware.

Microsoft's Skype communications app and the Visual Studio Code editor are also affected by the vulnerability.

Slack version 3.0.3 and the latest version of Skype for Windows have been patched against the flaw.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

CBA using facial recognition logins to verify disputed payments

CBA using facial recognition logins to verify disputed payments

Researchers demo AI-crippling GPUHammer attack

Researchers demo AI-crippling GPUHammer attack

Qantas obtains court order to prevent third-party access to stolen data

Qantas obtains court order to prevent third-party access to stolen data

Google Gemini for Workspace vulnerable to prompt injection attacks

Google Gemini for Workspace vulnerable to prompt injection attacks

Log In

  |  Forgot your password?