CVE-2026-34770

HIGH

CVSS v3

7

HIGH

EPSS Score

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected, the associated OS-level resources (a message window on Windows, a shutdown handler on macOS) retain dangling references. A subsequent session-change event (Windows) or system shutdown (macOS) derefer

Technical Details

CVSS v3 Vector
3.1
Published
4/4/2026
Last Modified
4/7/2026

Frequently Asked Questions

What is CVE-2026-34770?

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-free. After the native PowerMonitor object is garbage-collected, the associated OS-level resources (a message window on Windows, a shutdown handler on macOS) retain dangling references. A subsequent session-change event (Windows) or system shutdown (macOS) derefer

Is CVE-2026-34770 actively exploited?

Active exploitation of CVE-2026-34770 has not been confirmed. The EPSS score is N/A%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-34770?

CVE-2026-34770 has a CVSS v3 base score of 7 (HIGH severity), with vector string 3.1.

Is CVE-2026-34770 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.