<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 08:36:03 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-234298</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-234298</link>
      <description>EUVD-2026-234298</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-234298</guid>
    </item>
    <item>
      <title>fkie_cve-2022-21718</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21718</link>
      <description>&lt;p&gt;Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth device via the web bluetooth API if the app has not configured a custom `select-bluetooth-device` event handler. This has been patched and Electron versions `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` contain the fix. Code from the GitHub Security Advisory can be added to the app to work around the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth device via the web bluetooth API if the app has not configured a custom `select-bluetooth-device` event handler. This has been patched and Electron versions `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` contain the fix. Code from the GitHub Security Advisory can be added to the app to work around the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-21718</guid>
    </item>
    <item>
      <title>GHSA-3p22-ghq8-v749 — Renderers can obtain access to random bluetooth device without permission in Electron</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3p22-ghq8-v749</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: electron&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability allows renderers to obtain access to a random bluetooth device via the [web bluetooth API](https://developer.mozilla.org/en-US/docs/Web/API/Web_Bluetooth_API) if the app has not configured a custom `select-bluetooth-device` event handler.  The device that is accessed is random and the attacker would have no way of selecting a specific device.&lt;/p&gt;
&lt;p&gt;All current stable versions of Electron are affected.&lt;/p&gt;
&lt;p&gt;### Patches
This has been patched and the following Electron versions contain the fix:
* `17.0.0-alpha.6`
* `16.0.6`
* `15.3.5`
* `14.2.4`
* `13.6.6`&lt;/p&gt;
&lt;p&gt;### Workarounds
Adding this code to your app can workaround the issue.&lt;/p&gt;
&lt;p&gt;```js
app.on(&amp;#39;web-contents-created&amp;#39;, (event, webContents) =&amp;gt; {
  webContents.on(&amp;#39;select-bluetooth-device&amp;#39;, (event, devices, callback) =&amp;gt; {
    // Prevent default behavior
    event.preventDefault();
    // Cancel the request
    callback(&amp;#39;&amp;#39;);
  });
});
```&lt;/p&gt;
&lt;p&gt;For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: electron&lt;/p&gt;
&lt;p&gt;### Impact
This vulnerability allows renderers to obtain access to a random bluetooth device via the [web bluetooth API](https://developer.mozilla.org/en-US/docs/Web/API/Web_Bluetooth_API) if the app has not configured a custom `select-bluetooth-device` event handler.  The device that is accessed is random and the attacker would have no way of selecting a specific device.&lt;/p&gt;
&lt;p&gt;All current stable versions of Electron are affected.&lt;/p&gt;
&lt;p&gt;### Patches
This has been patched and the following Electron versions contain the fix:
* `17.0.0-alpha.6`
* `16.0.6`
* `15.3.5`
* `14.2.4`
* `13.6.6`&lt;/p&gt;
&lt;p&gt;### Workarounds
Adding this code to your app can workaround the issue.&lt;/p&gt;
&lt;p&gt;```js
app.on(&amp;#39;web-contents-created&amp;#39;, (event, webContents) =&amp;gt; {
  webContents.on(&amp;#39;select-bluetooth-device&amp;#39;, (event, devices, callback) =&amp;gt; {
    // Prevent default behavior
    event.preventDefault();
    // Cancel the request
    callback(&amp;#39;&amp;#39;);
  });
});
```&lt;/p&gt;
&lt;p&gt;For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3p22-ghq8-v749</guid>
    </item>
    <item>
      <title>gsd-2022-21718</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-21718</link>
      <description>gsd-2022-21718</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-21718</guid>
    </item>
  </channel>
</rss>
