Executive brief
Electron is a framework used to build desktop applications with web technologies. Applications using offscreen GPU rendering with shared textures can crash or suffer memory corruption if a release callback is invoked after the underlying memory has been freed. Only apps explicitly enabling shared-texture offscreen rendering are affected.
Technical details
A use-after-free vulnerability (CWE-416) exists in Electron's offscreen rendering implementation with GPU shared textures. The release() callback provided on a paint event texture can outlive its backing native state; invoking the callback after memory has been freed dereferences freed memory in the main process, potentially causing a crash or memory corruption. The vulnerability only affects applications that enable offscreen rendering with webPreferences.offscreen: { useSharedTexture: true }. Exploitation requires high privileges and local access. Patches are available in versions 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5 or later.
Affected products
- OpenJS Foundation Electron 33.0.0-alpha.1 to 39.8.4, 40.0.0-alpha.1 to 40.8.4, 41.0.0-alpha.1 to 41.0.x, 42.0.0-alpha.1 to 42.0.0-alpha.4
Timeline
- 2026-04-03: disclosed: Advisory published
- 2026-04-03: patched: Fixed in versions 39.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5