<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T08:36:27.843869+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-234298</id>
    <title>EUVD-2026-234298</title>
    <updated>2026-10-09T08:36:27.847046+00:00</updated>
    <content>EUVD-2026-234298</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-234298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21718</id>
    <title>fkie_cve-2022-21718</title>
    <updated>2026-10-09T08:36:27.847093+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth device via the web bluetooth API if the app has not configured a custom `select-bluetooth-device` event handler. This has been patched and Electron versions `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` contain the fix. Code from the GitHub Security Advisory can be added to the app to work around the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-21718"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3p22-ghq8-v749</id>
    <title>GHSA-3p22-ghq8-v749 — Renderers can obtain access to random bluetooth device without permission in Electron</title>
    <updated>2026-10-09T08:36:27.847150+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: electron</p>
<p>### Impact
This vulnerability allows renderers to obtain access to a random bluetooth device via the [web bluetooth API](https://developer.mozilla.org/en-US/docs/Web/API/Web_Bluetooth_API) if the app has not configured a custom `select-bluetooth-device` event handler.  The device that is accessed is random and the attacker would have no way of selecting a specific device.</p>
<p>All current stable versions of Electron are affected.</p>
<p>### Patches
This has been patched and the following Electron versions contain the fix:
* `17.0.0-alpha.6`
* `16.0.6`
* `15.3.5`
* `14.2.4`
* `13.6.6`</p>
<p>### Workarounds
Adding this code to your app can workaround the issue.</p>
<p>```js
app.on('web-contents-created', (event, webContents) =&gt; {
  webContents.on('select-bluetooth-device', (event, devices, callback) =&gt; {
    // Prevent default behavior
    event.preventDefault();
    // Cancel the request
    callback('');
  });
});
```</p>
<p>For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3p22-ghq8-v749"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-21718</id>
    <title>gsd-2022-21718</title>
    <updated>2026-10-09T08:36:27.847234+00:00</updated>
    <content>gsd-2022-21718</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-21718"/>
  </entry>
</feed>
