Intel

AIKIDO-2026-425093

electron is vulnerable to Use After Free

Use After FreeCVE-2026-9112 Published Jun 18, 2026

88

High Risk

This Affects:

JSelectron
40.0.0 - 40.10.2
Fixed in 40.10.3
Are you affected? Scan for Free

TL;DR

electron's embedded ANGLE GPU stack on Windows can free GPU resources while D3D11 transform-feedback state still references them. Remote pages that exercise GPU code paths can trigger the use-after-free. Pre-fix versions risk sandboxed arbitrary code execution through crafted HTML. The backport corrects buffer state tracking in transform feedback.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and ship electron desktop apps on Windows.

Background info

electron is vulnerable to Use After Free in versions 40.0.0 - 40.10.2.

How to fix this

Upgrade the electron library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform