Intel

AIKIDO-2026-10764

electron is vulnerable to Heap Corruption

Heap CorruptionCVE-2026-5859 Published May 7, 2026

88

High Risk

This Affects:

JSelectron
39.0.0 - 39.8.9
Fixed in 39.8.10
Are you affected? Scan for Free

TL;DR

Embedded Chromium’s WebML implementation can hit integer sizing mistakes that lead to heap corruption when hostile HTML drives specific ML operator paths. Attackers use normal remote content delivery to steer execution into unsafe pooling or indirection logic. That opens high-impact memory corruption consistent with Chrome’s critical severity classification for the defect class. Electron consumes the correction through synchronized Chromium cherry-picks shipped on its maintenance lines.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Heap Corruption in versions 39.0.0 - 39.8.9.

How to fix this

Upgrade the electron library to the patch version.