Intel

AIKIDO-2026-10913

electron is vulnerable to Memory Corruption

Memory Corruption Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 2 days ago

88

High Risk

This Affects:

JSelectron
40.0.0 - 40.10.0
Fixed in 40.10.1
41.0.0 - 41.6.1
Fixed in 41.7.0
42.0.0 - 42.1.0
Fixed in 42.2.0
Are you affected? Scan for Free

TL;DR

Electron bundles Chromium-family components that received upstream memory-safety and validation backports across media, GPU, UI, accessibility, Skia, ANGLE, and rendering paths. Crafted web or renderer-controlled content can reach use-after-free, heap overflow, integer overflow, and validation defects in those components. Pre-fix applications can expose users to crashes or memory corruption with potential process compromise through embedded Chromium functionality. The fix backports the upstream Chromium, ANGLE, and Skia patches into Electron's bundled dependencies.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Memory Corruption in versions 40.0.0 - 40.10.0, 41.0.0 - 41.6.1 and 42.0.0 - 42.1.0.

How to fix this

Upgrade the electron library to the patch version.