CVE-2026-34770
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected, the associated OS-level resources (a message window on Windows, a shutdown handler on macOS) retain dangling references. A subsequent session-change event (Windows) or system shutdown (macOS) dereferences freed memory, which may lead to a crash or memory corruption.
Leer descripción completaMostrar menos
All apps that access powerMonitor events (suspend, resume, lock-screen, etc.) are potentially affected. The issue is not directly renderer-controllable. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.29%
- Percentil entre todas las CVEs puntuadas: 19
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution75 % - Impacto principal
T1499.004Application or System Exploitationimpact65 % - Impacto secundario
T1565.001Stored Data Manipulationimpact55 %
Use-after-free en powerMonitor requiere interacción del usuario (UI:R) para disparar evento de sesión/apagado. El crash o corrupción de memoria puede causar DoS o manipulación de datos en memoria.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-416
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-34770",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-34770",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-04-07T00:00:00+00:00"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "electron",
"product": "electron",
"versions": [
{
"status": "affected",
"version": "< 38.8.6"
},
{
"status": "affected",
"version": ">= 39.0.0-alpha.1, < 39.8.1"
},
{
"status": "affected",
"version": ">= 40.0.0-alpha.1, < 40.8.0"
},
{
"status": "affected",
"version": ">= 41.0.0-alpha.1, < 41.0.0-beta.8"
}
]
}
]
}
],
"published": "2026-04-04T00:16:17.823",
"references": [
{
"url": "https://github.com/electron/electron/security/advisories/GHSA-jjp3-mq3x-295m",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-416"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected, the associated OS-level resources (a message window on Windows, a shutdown handler on macOS) retain dangling references. A subsequent session-change event (Windows) or system shutdown (macOS) dereferences freed memory, which may lead to a crash or memory corruption. All apps that access powerMonitor events (suspend, resume, lock-screen, etc.) are potentially affected. The issue is not directly renderer-controllable. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8."
},
{
"lang": "es",
"value": "Electron es un framework para escribir aplicaciones de escritorio multiplataforma usando JavaScript, HTML y CSS. Antes de las versiones 38.8.6, 39.8.1, 40.8.0 y 41.0.0-beta.8, las aplicaciones que usan el módulo powerMonitor pueden ser vulnerables a un uso después de liberación. Después de que el objeto nativo PowerMonitor es recolectado por el recolector de basura, los recursos asociados a nivel del SO (una ventana de mensaje en Windows, un gestor de apagado en macOS) retienen referencias colgantes. Un evento posterior de cambio de sesión (Windows) o un apagado del sistema (macOS) desreferencia la memoria liberada, lo que puede llevar a un fallo o corrupción de memoria. Todas las aplicaciones que acceden a los eventos de powerMonitor (suspender, reanudar, pantalla de bloqueo, etc.) están potencialmente afectadas. El problema no es directamente controlable por el renderizador. Este problema ha sido parcheado en las versiones 38.8.6, 39.8.1, 40.8.0 y 41.0.0-beta.8."
}
],
"lastModified": "2026-07-24T22:10:00.140",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "9CE003A2-03CC-4355-AA17-2CBD204EC6C3",
"versionEndExcluding": "38.8.6"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "8F28D187-306E-4C9D-ADED-56DD79B04AF3",
"versionEndExcluding": "39.8.1",
"versionStartIncluding": "39.0.0"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "450879B0-EFE3-43AE-BE1F-2456A9C74AA7",
"versionEndExcluding": "40.8.0",
"versionStartIncluding": "40.0.0"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha1:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "A20225D6-F435-4D09-962D-B162F521B6AD"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha2:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "33712802-EB60-4E9A-83B8-9F2320B70CB4"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha3:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "9D0A9142-54FE-47BB-9FEB-5E97528E28FE"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha4:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "9E1D191F-DEAE-4DB3-9822-F31AF9FE3BAC"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha5:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "45A8192F-3D2C-4987-9BBE-7ECC3F71965D"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:alpha6:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "EEA1A2E5-03DB-46CB-8427-7F31A8A7CE1C"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta1:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "B2DFCE75-BD3F-4537-B5B8-14097E262EA2"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta2:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "BC346E25-EA43-4615-8CDB-16D15D46E4FF"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta3:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "FA5B3C00-CAFC-4995-BF35-9920F3039E77"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta4:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "3672F3FB-6B5E-40FD-8A92-CB4DD6BC6A93"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta5:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "9EE4F8AE-21D2-4815-85B7-B7ECCC0D5059"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta6:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "D195760C-7DD9-4259-9042-EDE65AEAC1D6"
},
{
"criteria": "cpe:2.3:a:electronjs:electron:41.0.0:beta7:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "B370859F-24D3-4B25-B580-1A5B6DB94BFE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}