CVE-2026-34771
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
Record summary
CVE-2026-34771 has a selected CVSS score of 7.5 (high).
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that register an asynchronous session.setPermissionRequestHandler() may be vulnerable to a use-after-free when handling fullscreen, pointer-lock, or keyboard-lock permission requests. If the requesting frame navigates or the window closes while the permission handler is pending, invoking the stored callback dereferences freed memory, which may lead to a crash or memory corruption. Apps that do not set a permission request handler, or whose handler responds synchronously, are not affected. This issue has been patched in versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 7, 2026 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
Red Hat Build of Podman DesktopBrowse Red Hat / Red Hat Build of Podman Desktoppodman-desktop-macos-1-0Default status: affected | CVE List | Version data not supplied | |
Red Hat Build of Podman DesktopBrowse Red Hat / Red Hat Build of Podman Desktoppodman-desktop-windows-1-0Default status: affected | CVE List | Version data not supplied | |
Red Hat Build of Podman Desktop - Tech PreviewBrowse Red Hat / Red Hat Build of Podman Desktop - Tech Previewrhdesktop/rh-podman-desktop-ext-openshift-local-rhel10Default status: affected | CVE List | Version data not supplied | |
electronBrowse electron / electron | CVE List | < 38.8.6 | affected |
| >= 39.0.0-alpha.1, < 39.8.0 | affected | ||
| >= 40.0.0-alpha.1, < 40.7.0 | affected | ||
| >= 41.0.0-alpha.1, < 41.0.0-beta.8 | affected | ||
electronBrowse npm / electron | GitHub Advisory | Before 38.8.6 · Fixed in 38.8.6 | affected |
| 39.0.0-alpha.1 to < 39.8.0 · Fixed in 39.8.0 | affected | ||
| 40.0.0-alpha.1 to < 40.7.0 · Fixed in 40.7.0 | affected | ||
| 41.0.0-alpha.1 to < 41.0.0-beta.8 · Fixed in 41.0.0-beta.8 | affected | ||