


Perceptive Security
SOC/SIEM Consultancy

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-bet…
Published:
3 april 2026 om 22:00:00
Alert date:
4 april 2026 om 01:01:48
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
CVE-2026-34770 affects the Electron framework's powerMonitor module with a use-after-free vulnerability. The issue occurs when the native PowerMonitor object is garbage-collected while OS-level resources retain dangling references. Subsequent session-change events on Windows or system shutdown on macOS can dereference freed memory, leading to crashes or memory corruption. All applications using powerMonitor events (suspend, resume, lock-screen) are potentially affected. The vulnerability has been patched in Electron versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8.
Technical details
Mitigation steps:
Affected products:
Electron
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-34770
https://github.com/electron/electron/security/advisories/GHSA-jjp3-mq3x-295m
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
