Use-After-Free Vulnerability in Electron Framework by GitHub
CVE-2026-34772

5.8MEDIUM

Key Information:

Vendor

Electron

Status
Vendor
CVE Published:
3 April 2026

What is CVE-2026-34772?

The Electron framework, widely used for developing cross-platform desktop applications with web technologies, had a vulnerability that exposed apps to use-after-free issues. This flaw occurred when applications allowed downloads while simultaneously programmatically destroying sessions. If the session was terminated while a native save-file dialog was active, closing the dialog could lead to dereferencing freed memory, resulting in application crashes or potential memory corruption. Versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8 have implemented patches to address this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

electron < 38.8.6 < 38.8.6

electron >= 39.0.0-alpha.1, < 39.8.0 < 39.0.0-alpha.1, 39.8.0

electron >= 40.0.0-alpha.1, < 40.7.0 < 40.0.0-alpha.1, 40.7.0

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.