Junglewise Threat Intelligence

CVE-2026-34774: Electron use-after-free in offscreen child window paint callback

CVE-2026-34774 · Severity: high · CVSS 8.1 · Published 2026-04-04

Executive brief

Electron is a widely-used framework for building desktop applications with web technologies. A use-after-free vulnerability affects applications that use offscreen rendering and permit child windows to be opened. If a parent application window is destroyed while child windows remain open, subsequent paint operations can access freed memory, leading to crashes or potential memory corruption. Affected applications must use the specific offscreen rendering feature and allow child window creation to be vulnerable.

Technical details

This vulnerability is a use-after-free (CWE-416) in Electron's offscreen rendering subsystem. The root cause is improper lifecycle management of WebContents memory when parent offscreen renderers are destroyed while child windows remain open. Paint callback operations on the child window subsequently dereference memory that has been freed, potentially causing a crash or memory corruption. The vulnerability requires specific preconditions: applications must have webPreferences.offscreen set to true and their setWindowOpenHandler must permit child window creation. Network-reachable attack is possible but has high complexity. Patches are available in versions 39.8.1, 40.7.0, and 41.0.0.

Affected products

  • Electron Electron All versions before 39.8.1, versions 40.0.0-alpha.1 to 40.6.x, versions 41.0.0-alpha.1 to 40.9.x

Timeline

  • 2026-04-03: disclosed: Advisory published
  • 2026-04-03: patched: Patches released in versions 39.8.1, 40.7.0, and 41.0.0

References