Vulnerability in Electron-based Application: Unintentionally Giving Malicious Code Room to Run
ID: d0632837-8f99-5dae-8c10-c29a80ce82f0
STIX ID: report--d0632837-8f99-5dae-8c10-c29a80ce82f0
Feed Name: CertiK Blog
This report details a remote code execution vulnerability in the Symbol Electron desktop wallet caused by nodeIntegration being enabled in the Electron BrowserWindow configuration; an attacker able to inject or load remote JavaScript (e.g., via the app's News feature) can invoke Node.js modules (child_process) to execute system commands. The authors provide a proof-of-concept, show Symbol patched the issue (nodeIntegration set to false and blocking remote content), and reported a similar configuration issue to MyCrypto.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
