3.9
CVE-2026-70598
- EPSS 0.1%
- Veröffentlicht 05.08.2026 16:17:03
- Zuletzt bearbeitet 08.10.2026 13:54:22
- Erkennungen
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully validated by the main process. A compromised GPU process could cause the main process to read out-of-bounds memory while producing paint event images, disclosing memory or crashing the app. This issue is fixed in 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Electronjs ≫ Electron SwPlatform node.js Version < 39.8.10
Electronjs ≫ Electron SwPlatform node.js Version >= 40.0.0 < 40.9.0
Electronjs ≫ Electron SwPlatform node.js Version >= 41.0.0 < 41.2.1
Electronjs ≫ Electron Version 42.0.0 Update alpha1 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update alpha2 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update alpha3 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update alpha4 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update alpha5 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update alpha6 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update beta1 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update beta2 SwPlatform node.js
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.01 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 3.9 | 0.8 | 2.7 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
https://github.com/electron/electron/commit/2c24640e7b0b9c74fe9f44bce0fde138340ff4fb
https://github.com/electron/electron/security/advisories/GHSA-pfmc-3mgc-p6fp