Intel

AIKIDO-2026-882064

electron is vulnerable to Use After Free

Use After FreeCVE-2026-9114 Published 4 days ago

88

High Risk

This Affects:

JSelectron
40.0.0 - 40.10.2
Fixed in 40.10.3
41.0.0 - 41.7.1
Fixed in 41.7.2
Are you affected? Scan for Free

TL;DR

electron's embedded Chromium QUIC networking stack can use QUIC proxy socket memory after it is freed when handling malicious network traffic. Remote attackers can reach the faulty datagram client socket lifetime through QUIC-enabled connections. Pre-fix builds risk sandboxed code execution from network input. The backport adds advanced memory-safety checks on the vulnerable QUIC class as shipped upstream on Chrome stable.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

electron is vulnerable to Use After Free in versions 40.0.0 - 40.10.2 and 41.0.0 - 41.7.1.

How to fix this

Upgrade the electron library to the patch version.