CVE-2026-34780

Source
https://cve.org/CVERecord?id=CVE-2026-34780
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34780.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-34780
Aliases
Published
2026-04-04T00:02:02.224Z
Modified
2026-07-22T03:29:46.579112Z
Severity
  • 8.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Electron: Context Isolation bypass via contextBridge VideoFrame transfer
Details

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the contextBridge are vulnerable to a context isolation bypass. An attacker who can execute JavaScript in the main world (for example, via XSS) can use a bridged VideoFrame to gain access to the isolated world, including any Node.js APIs exposed to the preload script. Apps are only affected if a preload script returns, resolves, or passes a VideoFrame object to the main world via contextBridge.exposeInMainWorld(). Apps that do not bridge VideoFrame objects are not affected. This issue has been patched in versions 39.8.0, 40.7.0, and 41.0.0-beta.8.

Database specific
{
    "cwe_ids": [
        "CWE-1188",
        "CWE-668"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34780.json"
}
References

Affected packages

Git / github.com/electron/electron

Affected ranges

Type
GIT
Repo
https://github.com/electron/electron
Events
Database specific
{
    "cpe": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
    "extracted_events": [
        {
            "introduced": "39.0.0"
        },
        {
            "fixed": "39.8.0"
        },
        {
            "introduced": "40.0.0"
        },
        {
            "fixed": "40.7.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v39.*
v39.0.0
v39.0.1
v39.1.0
v39.1.1
v39.1.2
v39.2.0
v39.2.1
v39.2.2
v39.2.3
v39.2.4
v39.2.5
v39.2.6
v39.2.7
v39.3.0
v39.4.0
v39.5.0
v39.5.1
v39.5.2
v39.6.0
v39.6.1
v39.7.0
v40.*
v40.0.0
v40.1.0
v40.2.0
v40.2.1
v40.3.0
v40.4.0
v40.4.1
v40.5.0
v40.6.0
v40.6.1

Database specific

vanir_signatures_modified
"2026-07-22T03:29:46Z"
vanir_signatures
[
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "178675391894984138341889541690365973684",
                "219130035380057126897531452099541104002",
                "126028090964366337652820515559819811359"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
        "id": "CVE-2026-34780-04c47c2f",
        "target": {
            "file": "shell/browser/electron_permission_manager.h"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 290.0,
            "function_hash": "97039591253026817807654837533762377827"
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
        "id": "CVE-2026-34780-16120300",
        "target": {
            "function": "WebContents::RequestKeyboardLock",
            "file": "shell/browser/api/electron_api_web_contents.cc"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 291.0,
            "function_hash": "61142233835202829958084947734626901732"
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13",
        "id": "CVE-2026-34780-2ece3857",
        "target": {
            "function": "UsbChooserController::OnDeviceAdded",
            "file": "shell/browser/usb/usb_chooser_controller.cc"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "302647440730222286742065939401885204342",
                "213210996922622981944964345494938291300",
                "46110625459178329298984308919692078035",
                "308242114583160430057595766604657996435",
                "15808636014665415213704106777963377880",
                "23049463670308433760285037254266648460",
                "169983092099714675976652469175961167629",
                "220953584429958072043703509851474845330"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
        "id": "CVE-2026-34780-52d1698b",
        "target": {
            "file": "shell/browser/api/electron_api_web_contents.h"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 265.0,
            "function_hash": "96155712548337292400733261458234038190"
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13",
        "id": "CVE-2026-34780-7a17ee01",
        "target": {
            "function": "UsbChooserController::OnDeviceRemoved",
            "file": "shell/browser/usb/usb_chooser_controller.cc"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "156275209481195871206198604452347446054",
                "175877772127482286239303214206247257505",
                "71474498449249973993196248779216514511",
                "14940573484809719751531164629790354042",
                "190626596885386175352053396729627138744",
                "301807841628843703471653104348489734945",
                "134462277057499600728895058009828883701",
                "168811110514858893198152212864105933263",
                "240796529130563652804681646259279239661",
                "20980650432641246652071701519902713392",
                "134163468621777755879592738116157554787",
                "181675892745925892443378007541251482199",
                "53631146889017094540018286417166122202",
                "241994195701962275033055915236763659731",
                "75252833910771996883857281786435442585",
                "154658513830234467414558570821697542526",
                "228916837748401816059853777773564214152"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13",
        "id": "CVE-2026-34780-8cdb8f5e",
        "target": {
            "file": "shell/browser/usb/usb_chooser_controller.cc"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 421.0,
            "function_hash": "297327772576386591164750756102735457707"
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13",
        "id": "CVE-2026-34780-ad40a1da",
        "target": {
            "function": "UsbChooserController::OnDeviceChosen",
            "file": "shell/browser/usb/usb_chooser_controller.cc"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 694.0,
            "function_hash": "293482645540665903577029483346008950707"
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
        "id": "CVE-2026-34780-b29fc49a",
        "target": {
            "function": "WebContents::~WebContents",
            "file": "shell/browser/api/electron_api_web_contents.cc"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 417.0,
            "function_hash": "200189763688856902106236158256740166562"
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
        "id": "CVE-2026-34780-b73afd14",
        "target": {
            "function": "WebContents::EnterFullscreenModeForTab",
            "file": "shell/browser/api/electron_api_web_contents.cc"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 309.0,
            "function_hash": "142894579126557078612750465996125695405"
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
        "id": "CVE-2026-34780-bebe9c57",
        "target": {
            "function": "WebContents::RequestPointerLock",
            "file": "shell/browser/api/electron_api_web_contents.cc"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "172254940840651545307547467675269355390",
                "203776172793253186837188577032711806018",
                "292057948711896347295010900533229588006",
                "86626044662892447202740804354061256814",
                "302047480695382285029110301698887214484",
                "200523701153566048891738146168306534323",
                "224695972079447967607053995532785191113",
                "5516346858382603644295849184690449718",
                "272975537203403675984099548741835201505",
                "323679966937264236305706957393290082246",
                "167740096839072816910168742268814651714",
                "187115845473996675337174991740048671859",
                "19226079768645679789525655827032305715",
                "291620580006522488323469082307520992334",
                "321205863328364055224016726868757299699",
                "150332271850213351345388275646695595103",
                "225886463583132774994553655690143237585",
                "88922925232342227464352931942020322447",
                "204166832810991155569094000977144475182",
                "10127105033526569746140614845050393412",
                "136357128351224668959564582626865229772",
                "159122646162125252544582092365633912365",
                "197974183905236273378319630751641312316",
                "275365673647440653900725970873246504437",
                "257584571322843584030141831554521920399",
                "257160280229469026798715795645251610844",
                "46773167401156905844124568335873804315",
                "294806251294630468732661873797615442847",
                "163064322362209515105295693592644273463",
                "139352105874698319173624790048228061604",
                "14291476199439583193750193055633443327"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
        "id": "CVE-2026-34780-c094721e",
        "target": {
            "file": "shell/browser/api/electron_api_web_contents.cc"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "293520790029042136735839112743715105738",
                "99519798731736299611781643717627917549",
                "278020203046355500786065357035235163632",
                "330363439832660583890684009329944399467"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13",
        "id": "CVE-2026-34780-c3930a42",
        "target": {
            "file": "shell/browser/usb/usb_chooser_controller.h"
        }
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 695.0,
            "function_hash": "251157994721493377634460688639175075370"
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
        "id": "CVE-2026-34780-e7b4e66d",
        "target": {
            "function": "WebContents::OnEnterFullscreenModeForTab",
            "file": "shell/browser/api/electron_api_web_contents.cc"
        }
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "163598223645556799758809004922253860728",
                "328782403901881463597991084953359396933",
                "145653381957897113583178423854806299436"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
        "id": "CVE-2026-34780-f9bf6085",
        "target": {
            "file": "shell/browser/electron_permission_manager.cc"
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34780.json"