Improper Isolation or Compartmentalization
CVE-2026-34775
Summary
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.x prior to 39.8.4, 40.x prior to 40.8.4, and 41.x prior to 41.0.0, the "nodeIntegrationInWorker" webPreference was not correctly scoped in all configurations. In certain process-sharing scenarios, workers spawned in frames configured with "nodeIntegrationInWorker: false" could still receive Node.js integration. Apps are only affected if they enable "nodeIntegrationInWorker." Apps that do not use nodeIntegrationInWorker are not affected. This issue has been patched in versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-653 - Improper Isolation or Compartmentalization
The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.
References
Advisory Timeline
- Published