Cross-Site Scripting Vulnerability in Electron Framework
CVE-2026-34766
What is CVE-2026-34766?
A vulnerability in the Electron framework could expose desktop applications to improper device selection risks. The select-usb-device event callback fails to validate device IDs against a filtered list presented to the handler, potentially allowing malicious handlers to access unauthorized devices. While security-sensitive devices in the WebUSB blocklist remain protected, applications utilizing unconventional device-selection methods are at risk. This issue has been addressed in subsequent versions of the Electron framework, enhancing security and ensuring stricter compliance with device selection protocols.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
electron < 38.8.6 < 38.8.6
electron >= 39.0.0-alpha.1, < 39.8.0 < 39.0.0-alpha.1, 39.8.0
electron >= 40.0.0-alpha.1, < 40.7.0 < 40.0.0-alpha.1, 40.7.0
