CVE-2026-34780
HIGHDescription
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the contextBridge are vulnerable to a context isolation bypass. An attacker who can execute JavaScript in the main world (for example, via XSS) can use a bridged VideoFrame to gain access to the isolated world, including any Node.js APIs exposed to the preload script. Apps are only affected if a preload script returns, resolves, or passes a VideoFrame object to the main world via contextBridge.exposeInMainWorld(). Apps that do not bridge VideoFrame objects are not affected. This issue has been patched in versions 39.8.0, 40.7.0, and 41.0.0-beta.8.
How to fix
TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works
Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.
CVSS v3 Vector
Exploitability
Impact
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Exploit Intelligence
Low risk: more likely to be exploited than 25% of all known CVEs.
References
Related Vulnerabilities
Other CWE-668 vulnerabilities, ordered by exploit likelihood. View all
| CVE | Severity | CVSS | EPSS | Exploited | Fix |
|---|---|---|---|---|---|
| CVE-2022-39952 | Critical | 9.8 | 100% | - | Fix |
| CVE-2017-16597 | Critical | 9.8 | 57% | - | - |
| CVE-2017-16603 | High | 8.8 | 54% | - | - |
| CVE-2024-25153 | Critical | 9.8 | 42% | - | Fix |
| CVE-2022-25236 | Critical | 9.8 | 36% | - | Fix |
| CVE-2017-0215 | Medium | 5.3 | 36% | - | - |
Embed a live status badge for CVE-2026-34780
Markdown
[](https://tridentstack.com/cve/CVE-2026-34780)HTML
<a href="https://tridentstack.com/cve/CVE-2026-34780"><img src="https://tridentstack.com/cve/badge/CVE-2026-34780.svg" alt="CVE-2026-34780"></a>Find and fix vulnerabilities across your fleet
TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-07-15.