Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-34764 Details

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alpha.1 to before 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that use offscreen rendering with GPU shared textures may be vulnerable to a use-after-free. Under certain conditions, the release() callback provided on a paint event texture can outlive its backing native state, and invoking it after that point dereferences freed memory in the main process, which may lead to a crash or memory corruption. Apps are only affected if they use offscreen rendering with webPreferences.offscreen: { useSharedTexture: true }. Apps that do not enable shared-texture offscreen rendering are not affected. To mitigate this issue, ensure texture.release() is called promptly after the texture has been consumed, before the texture object becomes unreachable. This vulnerability is fixed in 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-416Use After Free[email protected]

Affected Products

ProductVersions
electronjs electron
>= 33.0.0, < 39.8.5
>= 40.0.0, < 40.8.5
>= 41.0.0, < 41.1.0
42.0.0 alpha1
42.0.0 alpha2

CPE

  • cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*
  • cpe:2.3:a:electronjs:electron:42.0.0:alpha1:*:*:*:node.js:*:*
  • cpe:2.3:a:electronjs:electron:42.0.0:alpha2:*:*:*:node.js:*:*
  • cpe:2.3:a:electronjs:electron:42.0.0:alpha3:*:*:*:node.js:*:*
  • cpe:2.3:a:electronjs:electron:42.0.0:alpha4:*:*:*:node.js:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-34764
NVD Published Date:
Apr 6, 2026
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2026-34764 Details - Not Deferred