Intel

AIKIDO-2026-425093

electron is vulnerable to Use After Free

Use After FreeCVE-2026-9112 Published 4 days ago

88

High Risk

This Affects:

JSelectron
40.0.0 - 40.10.2
Fixed in 40.10.3
Are you affected? Scan for Free

TL;DR

electron's embedded ANGLE GPU stack on Windows can free GPU resources while D3D11 transform-feedback state still references them. Remote pages that exercise GPU code paths can trigger the use-after-free. Pre-fix versions risk sandboxed arbitrary code execution through crafted HTML. The backport corrects buffer state tracking in transform feedback.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and ship electron desktop apps on Windows.

Background info

electron is vulnerable to Use After Free in versions 40.0.0 - 40.10.2.

How to fix this

Upgrade the electron library to the patch version.