Intel

AIKIDO-2026-471517

electron is vulnerable to Out-of-Bounds Read

Out-of-Bounds ReadCVE-2026-9122 Published 4 days ago

65

Medium Risk

This Affects:

JSelectron
40.0.0 - 40.10.2
Fixed in 40.10.3
41.0.0 - 41.7.1
Fixed in 41.7.2
Are you affected? Scan for Free

TL;DR

electron's embedded ANGLE Metal GPU path on macOS can compute incorrect pitch for compressed textures in pixel-buffer uploads. Crafted pages that drive compressed texture transfers can read beyond allocated buffers. Pre-fix versions may disclose sensitive GPU process memory. The backport corrects pitch computation for compressed texture PBO operations.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and ship electron desktop apps on macOS.

Background info

electron is vulnerable to Out-of-Bounds Read in versions 40.0.0 - 40.10.2 and 41.0.0 - 41.7.1.

How to fix this

Upgrade the electron library to the patch version.