Junglewise Threat Intelligence

CVE-2026-34764: Electron use-after-free in offscreen shared texture release() callback

CVE-2026-34764 · Severity: low · CVSS 3.1 · Published 2026-04-03

Vendors: OpenJS Foundation.

Executive brief

Electron is a framework used to build desktop applications with web technologies. Applications using offscreen GPU rendering with shared textures can crash or suffer memory corruption if a release callback is invoked after the underlying memory has been freed. Only apps explicitly enabling shared-texture offscreen rendering are affected.

Technical details

A use-after-free vulnerability (CWE-416) exists in Electron's offscreen rendering implementation with GPU shared textures. The release() callback provided on a paint event texture can outlive its backing native state; invoking the callback after memory has been freed dereferences freed memory in the main process, potentially causing a crash or memory corruption. The vulnerability only affects applications that enable offscreen rendering with webPreferences.offscreen: { useSharedTexture: true }. Exploitation requires high privileges and local access. Patches are available in versions 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5 or later.

Affected products

  • OpenJS Foundation Electron 33.0.0-alpha.1 to 39.8.4, 40.0.0-alpha.1 to 40.8.4, 41.0.0-alpha.1 to 41.0.x, 42.0.0-alpha.1 to 42.0.0-alpha.4

Timeline

  • 2026-04-03: disclosed: Advisory published
  • 2026-04-03: patched: Fixed in versions 39.8.5, 40.8.5, 41.1.0, 42.0.0-alpha.5

References