5.3

CVSS3.1

CVE-2026-34776 - Electron: Out-of-bounds read in second-instance IPC on macOS and Linux

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on macOS and Linux, apps that call app.requestSingleInstanceLock() were vulnerable to an out-of-bounds heap read when parsing a crafted secon…

📅 Published: April 3, 2026, 11:56 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

6.8

CVSS3.1

CVE-2026-34775 - Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInWorker webPreference was not correctly scoped in all configurations. In certain process-sharing scenarios, workers spawn…

📅 Published: April 3, 2026, 11:55 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

8.1

CVSS3.1

CVE-2026-34774 - Electron: Use-after-free in offscreen child window paint callback

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen rendering and allow child windows via window.open() may be vulnerable to a use-after-free. If the parent offscreen WebContent…

📅 Published: April 3, 2026, 11:52 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

4.7

CVSS3.1

CVE-2026-34773 - Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, on Windows, app.setAsDefaultProtocolClient(protocol) did not validate the protocol name before writing to the registry. Apps that pass untrus…

📅 Published: April 3, 2026, 11:50 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

5.8

CVSS3.1

CVE-2026-34772 - Electron: Use-after-free in download save dialog callback

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that allow downloads and programmatically destroy sessions may be vulnerable to a use-after-free. If a session is torn down while…

📅 Published: April 3, 2026, 11:49 p.m. 🔄 Last Modified: April 7, 2026, 1:20 p.m.

7.5

CVSS3.1

CVE-2026-34771 - Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission call…

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that register an asynchronous session.setPermissionRequestHandler() may be vulnerable to a use-after-free when handling fullscree…

📅 Published: April 3, 2026, 11:47 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

7

CVSS3.1

CVE-2026-34770 - Electron: Use-after-free in PowerMonitor on Windows and macOS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected…

📅 Published: April 3, 2026, 11:46 p.m. 🔄 Last Modified: April 8, 2026, 3:55 a.m.

3.9

CVSS3.1

CVE-2026-34768 - Electron: Unquoted executable path in app.setLoginItemSettings on Windows

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, on Windows, app.setLoginItemSettings({openAtLogin: true}) wrote the executable path to the Run registry key without quoting. If the ap…

📅 Published: April 3, 2026, 11:44 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

5.9

CVSS3.1

CVE-2026-34767 - Electron: HTTP Response Header Injection in custom protocol handlers and webRequest

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.3, 40.8.3, and 41.0.3, apps that register custom protocol handlers via protocol.handle() / protocol.registerSchemesAsPrivileged() or modify response headers via web…

📅 Published: April 3, 2026, 11:43 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.

3.3

CVSS3.1

CVE-2026-34766 - Electron: USB device selection not validated against filtered device list

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, the select-usb-device event callback did not validate the chosen device ID against the filtered list that was presented to the handler…

📅 Published: April 3, 2026, 11:35 p.m. 🔄 Last Modified: April 10, 2026, 9:45 a.m.
Total resulsts: 343825
Page 163 of 34,383
« previous page » next page
Filters