8.3
CVE-2026-34780
- EPSS 0.33%
- Veröffentlicht 04.04.2026 00:02:02
- Zuletzt bearbeitet 24.07.2026 22:10:00
- CVE-Watchlists
- Unerledigt
Electron: Context Isolation bypass via contextBridge VideoFrame transfer
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the contextBridge are vulnerable to a context isolation bypass. An attacker who can execute JavaScript in the main world (for example, via XSS) can use a bridged VideoFrame to gain access to the isolated world, including any Node.js APIs exposed to the preload script. Apps are only affected if a preload script returns, resolves, or passes a VideoFrame object to the main world via contextBridge.exposeInMainWorld(). Apps that do not bridge VideoFrame objects are not affected. This issue has been patched in versions 39.8.0, 40.7.0, and 41.0.0-beta.8.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Electronjs ≫ Electron SwPlatformnode.js Version >= 39.0.0 < 39.8.0
Electronjs ≫ Electron SwPlatformnode.js Version >= 40.0.0 < 40.7.0
Electronjs ≫ Electron Version41.0.0 Updatealpha1 SwPlatformnode.js
Electronjs ≫ Electron Version41.0.0 Updatealpha2 SwPlatformnode.js
Electronjs ≫ Electron Version41.0.0 Updatealpha3 SwPlatformnode.js
Electronjs ≫ Electron Version41.0.0 Updatealpha4 SwPlatformnode.js
Electronjs ≫ Electron Version41.0.0 Updatealpha5 SwPlatformnode.js
Electronjs ≫ Electron Version41.0.0 Updatealpha6 SwPlatformnode.js
Electronjs ≫ Electron Version41.0.0 Updatebeta1 SwPlatformnode.js
Electronjs ≫ Electron Version41.0.0 Updatebeta2 SwPlatformnode.js
Electronjs ≫ Electron Version41.0.0 Updatebeta3 SwPlatformnode.js
Electronjs ≫ Electron Version41.0.0 Updatebeta4 SwPlatformnode.js
Electronjs ≫ Electron Version41.0.0 Updatebeta5 SwPlatformnode.js
Electronjs ≫ Electron Version41.0.0 Updatebeta6 SwPlatformnode.js
Electronjs ≫ Electron Version41.0.0 Updatebeta7 SwPlatformnode.js
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.244 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| security-advisories@github.com | 8.3 | 1.6 | 6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
|
| 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | 8 | 1.3 | 6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
|
CWE-1188 Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.
CWE-501 Trust Boundary Violation
The product mixes trusted and untrusted data in the same data structure or structured message.
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
https://bugzilla.redhat.com/show_bug.cgi?id=2455020
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34780.json
https://github.com/electron/electron/security/advisories/GHSA-jfqg-hf23-qpw2
https://access.redhat.com/security/cve/CVE-2026-34780