Junglewise Threat Intelligence

CVE-2026-34777: Electron origin validation error in permission request handler

CVE-2026-34777 · Severity: medium · CVSS 5.4 · Published 2026-04-04

Technologies: ElectronJS Electron.

Executive brief

Electron is a popular framework used to build desktop applications like Slack, Discord, and VS Code. A security flaw exists where applications might incorrectly grant sensitive permissions (such as camera access or the ability to open external links) to untrusted third-party content embedded within the app. This happens because the app may mistake a request from an embedded frame for a request from the main, trusted application window.

Technical details

An origin validation error (CWE-346) exists in Electron's permission handling logic. When an iframe requests permissions for fullscreen, pointerLock, keyboardLock, openExternal, or media, the origin passed to the 'session.setPermissionRequestHandler()' callback is incorrectly set to the top-level page's origin instead of the iframe's actual origin. Attackers can exploit this by embedding malicious content that inherits the permissions of the trusted parent window if the application relies on the 'origin' parameter or 'webContents.getURL()' for authorization. The vulnerability is mitigated if developers manually verify 'details.requestingUrl'. Patches are available in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0.

Affected products

  • ElectronJS Electron < 38.8.6, 39.0.0-alpha.1 to < 39.8.1, 40.0.0-alpha.1 to < 40.8.1, 41.0.0-alpha.1 to < 41.0.0

Timeline

  • 2026-04-02: advisory: GitHub Security Advisory published
  • 2026-04-04: disclosed: CVE published to NVD

References