PT-2026-30000 · Electron · Electron
Published
2026-04-03
·
Updated
2026-04-04
·
CVE-2026-34770
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Electron versions prior to 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8
Description
Electron applications utilizing the
powerMonitor module may experience a use-after-free condition. Following the garbage collection of the native PowerMonitor object, OS-level resources retain references to freed memory. Subsequent system events, such as session changes on Windows or system shutdown on macOS, can then dereference this freed memory, potentially leading to crashes or memory corruption. Applications accessing powerMonitor events (suspend, resume, lock-screen, etc.) are potentially affected.Recommendations
Update to Electron version 38.8.6 or later
Update to Electron version 39.8.1 or later
Update to Electron version 40.8.0 or later
Update to Electron version 41.0.0-beta.8 or later
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Electron