Intel

AIKIDO-2026-10763

electron is vulnerable to Heap-based Buffer Overflow

Heap-based Buffer OverflowCVE-2026-5858 Published May 7, 2026

88

High Risk

This Affects:

JSelectron
39.0.0 - 39.8.9
Fixed in 39.8.10
Are you affected? Scan for Free

TL;DR

Embedded Chromium’s WebML path can mis-handle buffer sizing so crafted page content triggers memory corruption beyond intended bounds. Remote attackers can leverage typical browsing primitives to reach faulty tensor-style workloads and corrupt heap metadata. Successful exploitation can break renderer isolation assumptions and enable severe integrity impact under Chromium severity ratings. Electron pulls these fixes by cherry-picking the upstream Chromium commits bundled into its stable branch releases.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Heap-based Buffer Overflow in versions 39.0.0 - 39.8.9.

How to fix this

Upgrade the electron library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform