Protection Mechanism Failure in atom-shell
CVE-2025-9866
- atom-shell
- chromium
- chromiumembeddedframework.runtime
- electron
- electron-nightly
- electron-prebuilt
- org.webjars.npm:electron
- org.webjars.npm:electron-prebuilt
Summary
Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- REQUIRED
- NONE
- HIGH
- HIGH
CWE-693 - Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
References
Advisory Timeline
- Published