Intel

AIKIDO-2026-956056

electron is vulnerable to User Interface (UI) Misrepresentation of Critical Information

User Interface (UI) Misrepresentation of Critical InformationCVE-2026-9110 Published 4 days ago

42

Medium Risk

This Affects:

JSelectron
40.0.0 - 40.10.2
Fixed in 40.10.3
41.0.0 - 41.7.1
Fixed in 41.7.2
Are you affected? Scan for Free

TL;DR

electron's embedded Chromium UI layer on Windows can mis-handle drag state tracking when a renderer is already compromised. A crafted HTML page can influence UI presentation and enable spoofing of trusted interface elements. Before the fix, users could be misled by attacker-controlled UI overlays. The backport tracks in-progress drags with static state to close the inappropriate implementation path.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and ship electron desktop apps on Windows.

Background info

electron is vulnerable to User Interface (UI) Misrepresentation of Critical Information in versions 40.0.0 - 40.10.2 and 41.0.0 - 41.7.1.

How to fix this

Upgrade the electron library to the patch version.