PT-2026-30000 · Electron · Electron

Published

2026-04-03

·

Updated

2026-04-04

·

CVE-2026-34770

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Electron versions prior to 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8
Description Electron applications utilizing the powerMonitor module may experience a use-after-free condition. Following the garbage collection of the native PowerMonitor object, OS-level resources retain references to freed memory. Subsequent system events, such as session changes on Windows or system shutdown on macOS, can then dereference this freed memory, potentially leading to crashes or memory corruption. Applications accessing powerMonitor events (suspend, resume, lock-screen, etc.) are potentially affected.
Recommendations Update to Electron version 38.8.6 or later Update to Electron version 39.8.1 or later Update to Electron version 40.8.0 or later Update to Electron version 41.0.0-beta.8 or later

Fix

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2026-34770
GHSA-JJP3-MQ3X-295M

Affected Products

Electron