Intel

AIKIDO-2026-10763

electron is vulnerable to Heap-based Buffer Overflow

Heap-based Buffer OverflowCVE-2026-5858

88

High Risk

This Affects:

JSelectron
39.0.0 - 39.8.9
Fixed in 39.8.10
Are you affected? Scan for Free

TL;DR

Embedded Chromium’s WebML path can mis-handle buffer sizing so crafted page content triggers memory corruption beyond intended bounds. Remote attackers can leverage typical browsing primitives to reach faulty tensor-style workloads and corrupt heap metadata. Successful exploitation can break renderer isolation assumptions and enable severe integrity impact under Chromium severity ratings. Electron pulls these fixes by cherry-picking the upstream Chromium commits bundled into its stable branch releases.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Heap-based Buffer Overflow in versions 39.0.0 - 39.8.9.

How to fix this

Upgrade the electron library to the patch version.