CVE-2026-34771 is a high-severity use-after-free vulnerability affecting Electron applications that register asynchronous permission request handlers for fullscreen, pointer-lock, or keyboard-lock features. This flaw occurs when a requesting frame navigates or a window closes while a permission handler is pending, potentially leading to memory corruption or application crashes. Rated 7.5 HIGH on the CVSS scale, exploitation requires high attack complexity and user interaction, but can result in significant impact to confidentiality, integrity, and availability. There is currently no public exploit code available, and it is not listed on CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 38.8.6CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
>= 39.0.0, < 39.8.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
>= 40.0.0, < 40.7.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
41.0.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:41.0.0:alpha1:*:*:*:node.js:*:* | ||
41.0.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:41.0.0:alpha2:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.