CVE-2026-34772Disclosure(electronjs / electron)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch electronjs electron systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that allow downloads and programmatically destroy sessions may be vulnerable to a use-after-free. If a session is torn down while a native save-file dialog is open for a download, dismissing the dialog dereferences freed memory, which may lead to a crash or memory corruption. Apps that do not destroy sessions at runtime, or that do not permit downloads, are not affected. This issue has been patched in versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • electron

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
electron

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-04: 2Patch / Workaround · 2026-04-04: 104-04
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34772 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, a… https://www.cve.org/CVERecord?id=CVE-2026-34772

    Post summary

    The post is a brief disclosure of CVE-2026-34772, noting affected Electron versions and implicitly referencing patched releases, with no PoC, exploit, or technical specifics given.

    01010507
    57.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-34772 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, a… https://www.cve.org/CVERecord?id=CVE-2026-34772 ----- Traducción: CVE-2026-34772 Ele… http://infoflow.cloud`

    Post summary

    The tweet references CVE‑2026‑34772 and lists affected Electron framework versions, but offers no PoC, exploit details, or patch information.

    0000043
    67 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
Appelectronjselectron-node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-
Appelectronjselectron41.0.0node.js-

Explore more