Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the contextBridge are vulnerable to a context isolation bypass. An attacker who can execute JavaScript in the main world (for example, via XSS) can use a bridged VideoFrame to gain access to the isolated world, including any Node.js APIs exposed to the preload script. Apps are only affected if a preload script returns, resolves, or passes a VideoFrame object to the main world via contextBridge.exposeInMainWorld(). Apps that do not bridge VideoFrame objects are not affected. This issue has been patched in versions 39.8.0, 40.7.0, and 41.0.0-beta.8.
{
"cwe_ids": [
"CWE-1188",
"CWE-668"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34780.json"
}"2026-07-22T03:29:46Z"
[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"178675391894984138341889541690365973684",
"219130035380057126897531452099541104002",
"126028090964366337652820515559819811359"
]
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
"id": "CVE-2026-34780-04c47c2f",
"target": {
"file": "shell/browser/electron_permission_manager.h"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 290.0,
"function_hash": "97039591253026817807654837533762377827"
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
"id": "CVE-2026-34780-16120300",
"target": {
"function": "WebContents::RequestKeyboardLock",
"file": "shell/browser/api/electron_api_web_contents.cc"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 291.0,
"function_hash": "61142233835202829958084947734626901732"
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13",
"id": "CVE-2026-34780-2ece3857",
"target": {
"function": "UsbChooserController::OnDeviceAdded",
"file": "shell/browser/usb/usb_chooser_controller.cc"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"302647440730222286742065939401885204342",
"213210996922622981944964345494938291300",
"46110625459178329298984308919692078035",
"308242114583160430057595766604657996435",
"15808636014665415213704106777963377880",
"23049463670308433760285037254266648460",
"169983092099714675976652469175961167629",
"220953584429958072043703509851474845330"
]
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
"id": "CVE-2026-34780-52d1698b",
"target": {
"file": "shell/browser/api/electron_api_web_contents.h"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 265.0,
"function_hash": "96155712548337292400733261458234038190"
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13",
"id": "CVE-2026-34780-7a17ee01",
"target": {
"function": "UsbChooserController::OnDeviceRemoved",
"file": "shell/browser/usb/usb_chooser_controller.cc"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"156275209481195871206198604452347446054",
"175877772127482286239303214206247257505",
"71474498449249973993196248779216514511",
"14940573484809719751531164629790354042",
"190626596885386175352053396729627138744",
"301807841628843703471653104348489734945",
"134462277057499600728895058009828883701",
"168811110514858893198152212864105933263",
"240796529130563652804681646259279239661",
"20980650432641246652071701519902713392",
"134163468621777755879592738116157554787",
"181675892745925892443378007541251482199",
"53631146889017094540018286417166122202",
"241994195701962275033055915236763659731",
"75252833910771996883857281786435442585",
"154658513830234467414558570821697542526",
"228916837748401816059853777773564214152"
]
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13",
"id": "CVE-2026-34780-8cdb8f5e",
"target": {
"file": "shell/browser/usb/usb_chooser_controller.cc"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 421.0,
"function_hash": "297327772576386591164750756102735457707"
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13",
"id": "CVE-2026-34780-ad40a1da",
"target": {
"function": "UsbChooserController::OnDeviceChosen",
"file": "shell/browser/usb/usb_chooser_controller.cc"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 694.0,
"function_hash": "293482645540665903577029483346008950707"
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
"id": "CVE-2026-34780-b29fc49a",
"target": {
"function": "WebContents::~WebContents",
"file": "shell/browser/api/electron_api_web_contents.cc"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 417.0,
"function_hash": "200189763688856902106236158256740166562"
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
"id": "CVE-2026-34780-b73afd14",
"target": {
"function": "WebContents::EnterFullscreenModeForTab",
"file": "shell/browser/api/electron_api_web_contents.cc"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 309.0,
"function_hash": "142894579126557078612750465996125695405"
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
"id": "CVE-2026-34780-bebe9c57",
"target": {
"function": "WebContents::RequestPointerLock",
"file": "shell/browser/api/electron_api_web_contents.cc"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"172254940840651545307547467675269355390",
"203776172793253186837188577032711806018",
"292057948711896347295010900533229588006",
"86626044662892447202740804354061256814",
"302047480695382285029110301698887214484",
"200523701153566048891738146168306534323",
"224695972079447967607053995532785191113",
"5516346858382603644295849184690449718",
"272975537203403675984099548741835201505",
"323679966937264236305706957393290082246",
"167740096839072816910168742268814651714",
"187115845473996675337174991740048671859",
"19226079768645679789525655827032305715",
"291620580006522488323469082307520992334",
"321205863328364055224016726868757299699",
"150332271850213351345388275646695595103",
"225886463583132774994553655690143237585",
"88922925232342227464352931942020322447",
"204166832810991155569094000977144475182",
"10127105033526569746140614845050393412",
"136357128351224668959564582626865229772",
"159122646162125252544582092365633912365",
"197974183905236273378319630751641312316",
"275365673647440653900725970873246504437",
"257584571322843584030141831554521920399",
"257160280229469026798715795645251610844",
"46773167401156905844124568335873804315",
"294806251294630468732661873797615442847",
"163064322362209515105295693592644273463",
"139352105874698319173624790048228061604",
"14291476199439583193750193055633443327"
]
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
"id": "CVE-2026-34780-c094721e",
"target": {
"file": "shell/browser/api/electron_api_web_contents.cc"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"293520790029042136735839112743715105738",
"99519798731736299611781643717627917549",
"278020203046355500786065357035235163632",
"330363439832660583890684009329944399467"
]
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13",
"id": "CVE-2026-34780-c3930a42",
"target": {
"file": "shell/browser/usb/usb_chooser_controller.h"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 695.0,
"function_hash": "251157994721493377634460688639175075370"
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
"id": "CVE-2026-34780-e7b4e66d",
"target": {
"function": "WebContents::OnEnterFullscreenModeForTab",
"file": "shell/browser/api/electron_api_web_contents.cc"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"163598223645556799758809004922253860728",
"328782403901881463597991084953359396933",
"145653381957897113583178423854806299436"
]
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa",
"id": "CVE-2026-34780-f9bf6085",
"target": {
"file": "shell/browser/electron_permission_manager.cc"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34780.json"