Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully validated by the main process. A compromised GPU process could cause the main process to read out-of-bounds memory while producing paint event images, disclosing memory or crashing the app. This issue is fixed in 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3.
{
"cwe_ids": [
"CWE-125"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70598.json"
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "39.8.10"
},
{
"introduced": "40.0.0-alpha.1"
},
{
"fixed": "40.9.0"
},
{
"introduced": "41.0.0-alpha.1"
},
{
"fixed": "41.2.1"
},
{
"introduced": "42.0.0-alpha.1"
},
{
"fixed": "42.0.0-beta.3"
}
]
}[
{
"digest": {
"length": 490.0,
"function_hash": "272553221120290705100734388975204268805"
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/8ee008ad48671e179d1b8258879871709babfff3",
"signature_type": "Function",
"target": {
"file": "shell/browser/api/electron_api_web_contents.cc",
"function": "WebContents::SetHtmlApiFullscreen"
},
"signature_version": "v1",
"id": "CVE-2026-70598-12b8aaae"
},
{
"digest": {
"length": 258.0,
"function_hash": "210013508323093177297460475453440803479"
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/2c24640e7b0b9c74fe9f44bce0fde138340ff4fb",
"signature_type": "Function",
"target": {
"file": "shell/browser/osr/osr_host_display_client.cc",
"function": "LayeredWindowUpdater::Draw"
},
"signature_version": "v1",
"id": "CVE-2026-70598-3b70866f"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"52985269102898246271683290925751234742",
"299701247432079879157113572265918430713",
"276984672316403808243651165576339342614",
"66898767996361537948729874370252986303",
"90211257474236163527820593179074083781",
"166976259638824740268604925536849881185",
"179473481588541596053754551634210636125",
"259154232663655695809000873693913957752",
"293554347403166080459471329205949076780",
"290102029854372705951516918382084975065",
"99257917486717488716841781023022129425",
"302548750777510051475390898108274388265",
"181614359652899065449753516754012818603",
"233520333118033317589059540749498779324",
"319751907310115586727278233382926690803",
"72576038054339931319379532711897791384",
"41043008074183195184578947966277852473",
"85970110964533078055605246667588680887",
"81922099629696529423663558748316276730",
"42405888709469132661457531460859319065",
"95609936160801958710960375661945344046",
"58396299684554309032011358610709888955",
"275706979691389989349329396571512506782",
"143921976515737074559289965729218557312",
"274678128171502483574347330551289731870"
]
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/2c24640e7b0b9c74fe9f44bce0fde138340ff4fb",
"signature_type": "Line",
"target": {
"file": "shell/browser/osr/osr_host_display_client.cc"
},
"signature_version": "v1",
"id": "CVE-2026-70598-4c317035"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"15682146902651291502359085377717075897",
"276527650456380695295071685428336688423",
"74027944338977948308663562070351154643",
"239644526509655375329227422095204640925"
]
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/8ee008ad48671e179d1b8258879871709babfff3",
"signature_type": "Line",
"target": {
"file": "shell/browser/api/electron_api_web_contents.cc"
},
"signature_version": "v1",
"id": "CVE-2026-70598-60dfa0b4"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"132499324170180748065020708904455569500",
"38580852441599850062545933635153300027",
"286557952056816869828842483616777493335",
"308955900204896901790724058279942896202",
"56774103734719937386381210706795076389",
"197390937822244451630759256400395708376",
"159053586338841126833715710277835328760",
"170133094357086791691081058479648480860",
"10317269603209100059262204786470312472",
"232843557910206273545414963633259929001",
"203032254595066202520228271085901875923",
"269437019204568539592945846005212216939",
"98744557272430749092213815724897528297",
"80775837756613340121391860941471740864",
"142720861266119996478617612793904141250"
]
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/2c24640e7b0b9c74fe9f44bce0fde138340ff4fb",
"signature_type": "Line",
"target": {
"file": "shell/browser/osr/osr_video_consumer.cc"
},
"signature_version": "v1",
"id": "CVE-2026-70598-6f70b1d4"
},
{
"digest": {
"length": 836.0,
"function_hash": "284948529000706989767278643474653488659"
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/2c24640e7b0b9c74fe9f44bce0fde138340ff4fb",
"signature_type": "Function",
"target": {
"file": "shell/browser/osr/osr_host_display_client.cc",
"function": "LayeredWindowUpdater::OnAllocatedSharedMemory"
},
"signature_version": "v1",
"id": "CVE-2026-70598-aab4efe5"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70598.json"
"2026-08-07T14:48:35Z"