Intel

AIKIDO-2026-38706

electron is vulnerable to Heap-based Buffer Overflow

Heap-based Buffer OverflowCVE-2026-9119 Published 4 days ago

88

High Risk

This Affects:

JSelectron
40.0.0 - 40.10.2
Fixed in 40.10.3
Are you affected? Scan for Free

TL;DR

electron's bundled WebRTC audio path can overflow heap buffers when crossfading from comfort-noise or expand frames to normal frames with mismatched vector sizes. Crafted HTML that drives WebRTC audio streams can supply inconsistent frame sizes. Pre-fix builds risk sandboxed memory corruption and code execution. The backport validates vector sizes before performing the crossfade.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Heap-based Buffer Overflow in versions 40.0.0 - 40.10.2.

How to fix this

Upgrade the electron library to the patch version.