8.1
CVE-2026-34774
- EPSS 0.44%
- Veröffentlicht 03.04.2026 23:52:38
- Zuletzt bearbeitet 24.07.2026 22:10:00
- Erkennungen
Electron: Use-after-free in offscreen child window paint callback
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen rendering and allow child windows via window.open() may be vulnerable to a use-after-free. If the parent offscreen WebContents is destroyed while a child window remains open, subsequent paint frames on the child dereference freed memory, which may lead to a crash or memory corruption. Apps are only affected if they use offscreen rendering (webPreferences.offscreen: true) and their setWindowOpenHandler permits child windows. Apps that do not use offscreen rendering, or that deny child windows, are not affected. This issue has been patched in versions 39.8.1, 40.7.0, and 41.0.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Electronjs ≫ Electron SwPlatform node.js Version < 39.8.1
Electronjs ≫ Electron SwPlatform node.js Version >= 40.0.0 < 40.7.0
Electronjs ≫ Electron Version 41.0.0 Update alpha1 SwPlatform node.js
Electronjs ≫ Electron Version 41.0.0 Update alpha2 SwPlatform node.js
Electronjs ≫ Electron Version 41.0.0 Update alpha3 SwPlatform node.js
Electronjs ≫ Electron Version 41.0.0 Update alpha4 SwPlatform node.js
Electronjs ≫ Electron Version 41.0.0 Update alpha5 SwPlatform node.js
Electronjs ≫ Electron Version 41.0.0 Update alpha6 SwPlatform node.js
Electronjs ≫ Electron Version 41.0.0 Update beta1 SwPlatform node.js
Electronjs ≫ Electron Version 41.0.0 Update beta2 SwPlatform node.js
Electronjs ≫ Electron Version 41.0.0 Update beta3 SwPlatform node.js
Electronjs ≫ Electron Version 41.0.0 Update beta4 SwPlatform node.js
Electronjs ≫ Electron Version 41.0.0 Update beta5 SwPlatform node.js
Electronjs ≫ Electron Version 41.0.0 Update beta6 SwPlatform node.js
Electronjs ≫ Electron Version 41.0.0 Update beta7 SwPlatform node.js
Electronjs ≫ Electron Version 41.0.0 Update beta8 SwPlatform node.js
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.44% | 0.355 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-416 Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CWE-825 Expired Pointer Dereference
The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.
https://bugzilla.redhat.com/show_bug.cgi?id=2455026
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34774.json
https://github.com/electron/electron/security/advisories/GHSA-532v-xpq5-8h95
https://access.redhat.com/security/cve/CVE-2026-34774