Skip to main content
← Back to Demos
SBOM advanced · 15 min

Electron App Ships Outdated Chromium with CVEs

On July 15, 2026, security researchers reported that compromised AsyncAPI npm packages deployed multi-stage botnet malware targeting CI/CD pipelines and developer environments, exploiting the trust placed in widely used open-source packages. Desktop applications built on Electron face a similar supply-chain risk: they bundle their own Chromium runtime, and outdated bundles ship known vulnerabilities straight to the endpoint. This demo scans a benign Electron sample and its bundled components. MetaDefender SBOM generates a software bill of materials for the application, maps every bundled library to known CVE databases, and surfaces vulnerable components such as outdated Chromium before distribution.

Attack Technique

Vulnerable app framework

MITRE ATT&CK

T1195 ↗

Platforms

linux

File Types

.json

MetaDefender Capabilities

SBOM

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---