Electron disclosed two high-severity vulnerabilities affecting desktop applications built on the framework, including a context isolation bypass tracked as CVE-2026-34780 and a use-after-free bug tracked as CVE-2026-34774. The first flaw lets an attacker who can run JavaScript in the main world—such as through XSS—abuse WebCodecs VideoFrame objects passed across contextBridge to reach the isolated world and potentially access Node.js APIs exposed by preload scripts. It affects Electron 39.0.0-alpha.1 through before 39.8.0, 40.0.0-alpha.1 through before 40.7.0, and 41.0.0-alpha.1 through before 41.0.0-beta.8.
The second issue affects applications that use offscreen rendering and allow child windows via window.open(). If a parent offscreen WebContents is destroyed while a child window remains open, later paint callbacks in the child can dereference freed memory, leading to crashes or memory corruption. Electron patched the flaws in versions 39.8.0, 40.7.0, and 41.0.0-beta.8 for CVE-2026-34780, and in 39.8.1, 40.7.0, and 41.0.0 for CVE-2026-34774; apps that do not pass VideoFrame objects through contextBridge, do not enable offscreen rendering, or block child windows are not exposed to the respective bugs.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Electron disclosed CVE-2026-34774, a use-after-free vulnerability in offscreen child window paint handling when a parent offscreen WebContents is destroyed while a child window remains open. The flaw affects versions prior to 39.8.1, 40.7.0, and 41.0.0, and Electron patched it in those releases.
Electron disclosed CVE-2026-34780, a context isolation bypass involving WebCodecs VideoFrame objects passed across contextBridge. The issue affects Electron 39.0.0-alpha.1 through before 39.8.0, 40.0.0-alpha.1 through before 40.7.0, and 41.0.0-alpha.1 through before 41.0.0-beta.8, and was patched in versions 39.8.0, 40.7.0, and 41.0.0-beta.8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.