Skip to main content

Exposure of Sensitive Information Through Metadata in atom-shell

CVE-2025-1921

  • atom-shell
  • chromium
  • chromiumembeddedframework.runtime
  • electron
  • electron-nightly
  • electron-prebuilt
  • org.webjars.npm:electron
  • org.webjars.npm:electron-prebuilt
Severity Medium
Score 6.5/10

Summary

Inappropriate implementation in Media Stream in Google Chrome prior to 134.0.6998.35 allowed a remote attacker to obtain information about a peripheral via a crafted HTML page.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • REQUIRED
  • NONE
  • HIGH
  • NONE

CWE-1230 - Exposure of Sensitive Information Through Metadata

The product prevents direct access to a resource containing sensitive information, but it does not sufficiently limit access to metadata that is derived from the original, sensitive information.

Advisory Timeline

  • Published