Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| electron(npm) | 0 | 22.3.25 | N/A |
| electron(npm) | 24.0.0 | 24.8.5 | N/A |
| electron(npm) | 25.0.0 | 25.8.4 | N/A |
| electron(npm) | 26.0.0 | 26.2.4 | N/A |
| electron(npm) | 27.0.0-alpha.1 | 27.0.0-beta.8 | N/A |
CVSS Metrics