Executive brief
Electron is a popular framework used to build desktop applications like Slack, Discord, and VS Code. A flaw in how the framework handles power-related events (like computer sleep or shutdown) could cause an application to crash or allow for unauthorized memory access. This occurs when the application tries to use system resources that have already been cleaned up by the computer's memory management system.
Technical details
A use-after-free vulnerability exists in Electron's powerMonitor module due to improper lifecycle management of native OS resources. When the native PowerMonitor object is garbage-collected, OS-level resources—specifically message windows on Windows and shutdown handlers on macOS—retain dangling references to the freed memory. An exploit is triggered when a subsequent system event, such as a session change or shutdown, attempts to dereference this memory. While not directly controllable from the renderer process, it can lead to memory corruption or arbitrary code execution in the main process. The issue is patched in versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8.
Affected products
- ElectronJS Electron < 38.8.6, >= 39.0.0-alpha.1 < 39.8.1, >= 40.0.0-alpha.1 < 40.8.0, >= 41.0.0-alpha.1 < 41.0.0-beta.8
Timeline
- 2026-04-02: advisory: GitHub Security Advisory published
- 2026-04-04: disclosed: CVE published to NVD