ArchLinux: 201911-7: electron: arbitrary code execution
Summary
A use-after-free vulnerability has been found in the audio component of the chromium browser before 78.0.3904.87. Google is aware of reports that an exploit for this vulnerability exists in the wild.
Resolution
Upgrade to 7.0.1-1.
# pacman -Syu "electron>=7.0.1-1"
The problem has been fixed upstream in version 7.0.1.
References
https://github.com/electron/electron/commit/25b3ee29cf9a8e3f59dcbabf7345b5b1360cd056 https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html https://security.archlinux.org/CVE-2019-13720
Workaround
None.