CVE-2026-34780 describes a high-severity context isolation bypass vulnerability in Electron, affecting versions 39.x, 40.x, and 41.x, specifically when applications bridge VideoFrame objects across the contextBridge. Rated 8.3 HIGH, an attacker who can execute JavaScript in the main world (e.g., via XSS) can leverage this to gain access to the isolated world and Node.js APIs, leading to full application compromise. Exploitation requires high attack complexity and user interaction, relying on specific application configurations and a prior compromise. While there is no public exploit code or evidence of active exploitation, the CVE is on the Hot List and has garnered some community discussion. Organizations should update to patched versions 39.8.0, 40.7.0, or 41.0.0-beta.8 if affected.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 39.0.0, < 39.8.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
>= 40.0.0, < 40.7.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:* | ||
41.0.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:41.0.0:alpha1:*:*:*:node.js:*:* | ||
41.0.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:41.0.0:alpha2:*:*:*:node.js:*:* | ||
41.0.0CPE matchmatch criteria | cpe:2.3:a:electronjs:electron:41.0.0:alpha3:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.