Executive brief
Electron, a popular framework for building desktop applications like Slack and Discord, is vulnerable to a security bypass. If an application handles video data in a specific way, an attacker could potentially break out of the restricted web environment to access sensitive system-level functions. This could lead to full control over the user's application or data if they interact with malicious content.
Technical details
A context isolation bypass exists in Electron when VideoFrame objects from the WebCodecs API are passed across the contextBridge. The vulnerability occurs if a preload script returns, resolves, or passes a VideoFrame object to the main world via contextBridge.exposeInMainWorld(). An attacker who can execute JavaScript in the main world (e.g., via XSS) can leverage the bridged VideoFrame to access the isolated world and any Node.js APIs exposed to the preload script. This issue is tracked as CWE-668 and CWE-501. Patches are available in versions 39.8.0, 40.7.0, and 41.0.0-beta.8.
Affected products
- ElectronJS Electron >= 39.0.0-alpha.1, < 39.8.0; >= 40.0.0-alpha.1, < 40.7.0; >= 41.0.0-alpha.1, < 41.0.0-beta.8
- Red Hat Red Hat Build of Podman Desktop 1
Timeline
- 2026-04-02: advisory: GitHub advisory published by Electron maintainers
- 2026-04-04: disclosed: CVE published to NVD
- 2026-04-04: patched: Patched versions released