{"id":"CVE-2026-34780","summary":"Electron: Context Isolation bypass via contextBridge VideoFrame transfer","details":"Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39.0.0-alpha.1 to before 39.8.0, 40.0.0-alpha.1 to before 40.7.0, and 41.0.0-alpha.1 to before 41.0.0-beta.8, apps that pass VideoFrame objects (from the WebCodecs API) across the contextBridge are vulnerable to a context isolation bypass. An attacker who can execute JavaScript in the main world (for example, via XSS) can use a bridged VideoFrame to gain access to the isolated world, including any Node.js APIs exposed to the preload script. Apps are only affected if a preload script returns, resolves, or passes a VideoFrame object to the main world via contextBridge.exposeInMainWorld(). Apps that do not bridge VideoFrame objects are not affected. This issue has been patched in versions 39.8.0, 40.7.0, and 41.0.0-beta.8.","aliases":["GHSA-jfqg-hf23-qpw2"],"modified":"2026-07-22T03:29:46.579112Z","published":"2026-04-04T00:02:02.224Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-1188","CWE-668"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34780.json"},"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34780.json"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-34780"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34780.json"},{"type":"ADVISORY","url":"https://github.com/electron/electron/security/advisories/GHSA-jfqg-hf23-qpw2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34780"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2455020"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/electron/electron","events":[{"introduced":"0abda746eabbca48066f7425c5db5dba53bb37f5"},{"fixed":"69c8cbf259da0f84e9c1db04958516a68f7170aa"},{"introduced":"35b8855913a75fbb6ee8b1465388c033535da634"},{"fixed":"1598b9116daef641157c557153dc5d3b809fdf13"}],"database_specific":{"cpe":"cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"39.0.0"},{"fixed":"39.8.0"},{"introduced":"40.0.0"},{"fixed":"40.7.0"}],"source":"CPE_RANGE"}}],"versions":["v39.7.0","v40.6.1","v40.6.0","v39.6.1","v40.5.0","v39.6.0","v40.4.1","v40.4.0","v40.3.0","v39.5.2","v40.2.1","v40.2.0","v39.5.1","v39.5.0","v39.4.0","v40.1.0","v39.3.0","v40.0.0","v39.2.7","v39.2.6","v39.2.5","v39.2.4","v39.2.3","v39.2.2","v39.2.1","v39.2.0","v39.1.2","v39.1.1","v39.1.0","v39.0.1","v39.0.0"],"database_specific":{"vanir_signatures_modified":"2026-07-22T03:29:46Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["178675391894984138341889541690365973684","219130035380057126897531452099541104002","126028090964366337652820515559819811359"],"threshold":0.9},"id":"CVE-2026-34780-04c47c2f","signature_type":"Line","signature_version":"v1","source":"https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa","target":{"file":"shell/browser/electron_permission_manager.h"}},{"source":"https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa","target":{"file":"shell/browser/api/electron_api_web_contents.cc","function":"WebContents::RequestKeyboardLock"},"deprecated":false,"digest":{"function_hash":"97039591253026817807654837533762377827","length":290},"id":"CVE-2026-34780-16120300","signature_type":"Function","signature_version":"v1"},{"digest":{"function_hash":"61142233835202829958084947734626901732","length":291},"id":"CVE-2026-34780-2ece3857","signature_type":"Function","signature_version":"v1","source":"https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13","target":{"file":"shell/browser/usb/usb_chooser_controller.cc","function":"UsbChooserController::OnDeviceAdded"},"deprecated":false},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["302647440730222286742065939401885204342","213210996922622981944964345494938291300","46110625459178329298984308919692078035","308242114583160430057595766604657996435","15808636014665415213704106777963377880","23049463670308433760285037254266648460","169983092099714675976652469175961167629","220953584429958072043703509851474845330"]},"id":"CVE-2026-34780-52d1698b","signature_type":"Line","signature_version":"v1","source":"https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa","target":{"file":"shell/browser/api/electron_api_web_contents.h"}},{"deprecated":false,"digest":{"function_hash":"96155712548337292400733261458234038190","length":265},"id":"CVE-2026-34780-7a17ee01","signature_type":"Function","signature_version":"v1","source":"https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13","target":{"file":"shell/browser/usb/usb_chooser_controller.cc","function":"UsbChooserController::OnDeviceRemoved"}},{"id":"CVE-2026-34780-8cdb8f5e","signature_type":"Line","signature_version":"v1","source":"https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13","target":{"file":"shell/browser/usb/usb_chooser_controller.cc"},"deprecated":false,"digest":{"line_hashes":["156275209481195871206198604452347446054","175877772127482286239303214206247257505","71474498449249973993196248779216514511","14940573484809719751531164629790354042","190626596885386175352053396729627138744","301807841628843703471653104348489734945","134462277057499600728895058009828883701","168811110514858893198152212864105933263","240796529130563652804681646259279239661","20980650432641246652071701519902713392","134163468621777755879592738116157554787","181675892745925892443378007541251482199","53631146889017094540018286417166122202","241994195701962275033055915236763659731","75252833910771996883857281786435442585","154658513830234467414558570821697542526","228916837748401816059853777773564214152"],"threshold":0.9}},{"deprecated":false,"digest":{"function_hash":"297327772576386591164750756102735457707","length":421},"id":"CVE-2026-34780-ad40a1da","signature_type":"Function","signature_version":"v1","source":"https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13","target":{"function":"UsbChooserController::OnDeviceChosen","file":"shell/browser/usb/usb_chooser_controller.cc"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa","target":{"file":"shell/browser/api/electron_api_web_contents.cc","function":"WebContents::~WebContents"},"deprecated":false,"digest":{"function_hash":"293482645540665903577029483346008950707","length":694},"id":"CVE-2026-34780-b29fc49a"},{"target":{"file":"shell/browser/api/electron_api_web_contents.cc","function":"WebContents::EnterFullscreenModeForTab"},"deprecated":false,"digest":{"function_hash":"200189763688856902106236158256740166562","length":417},"id":"CVE-2026-34780-b73afd14","signature_type":"Function","signature_version":"v1","source":"https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa"},{"deprecated":false,"digest":{"function_hash":"142894579126557078612750465996125695405","length":309},"id":"CVE-2026-34780-bebe9c57","signature_type":"Function","signature_version":"v1","source":"https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa","target":{"file":"shell/browser/api/electron_api_web_contents.cc","function":"WebContents::RequestPointerLock"}},{"signature_version":"v1","source":"https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa","target":{"file":"shell/browser/api/electron_api_web_contents.cc"},"deprecated":false,"digest":{"line_hashes":["172254940840651545307547467675269355390","203776172793253186837188577032711806018","292057948711896347295010900533229588006","86626044662892447202740804354061256814","302047480695382285029110301698887214484","200523701153566048891738146168306534323","224695972079447967607053995532785191113","5516346858382603644295849184690449718","272975537203403675984099548741835201505","323679966937264236305706957393290082246","167740096839072816910168742268814651714","187115845473996675337174991740048671859","19226079768645679789525655827032305715","291620580006522488323469082307520992334","321205863328364055224016726868757299699","150332271850213351345388275646695595103","225886463583132774994553655690143237585","88922925232342227464352931942020322447","204166832810991155569094000977144475182","10127105033526569746140614845050393412","136357128351224668959564582626865229772","159122646162125252544582092365633912365","197974183905236273378319630751641312316","275365673647440653900725970873246504437","257584571322843584030141831554521920399","257160280229469026798715795645251610844","46773167401156905844124568335873804315","294806251294630468732661873797615442847","163064322362209515105295693592644273463","139352105874698319173624790048228061604","14291476199439583193750193055633443327"],"threshold":0.9},"id":"CVE-2026-34780-c094721e","signature_type":"Line"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/electron/electron/commit/1598b9116daef641157c557153dc5d3b809fdf13","target":{"file":"shell/browser/usb/usb_chooser_controller.h"},"deprecated":false,"digest":{"line_hashes":["293520790029042136735839112743715105738","99519798731736299611781643717627917549","278020203046355500786065357035235163632","330363439832660583890684009329944399467"],"threshold":0.9},"id":"CVE-2026-34780-c3930a42"},{"signature_version":"v1","source":"https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa","target":{"function":"WebContents::OnEnterFullscreenModeForTab","file":"shell/browser/api/electron_api_web_contents.cc"},"deprecated":false,"digest":{"length":695,"function_hash":"251157994721493377634460688639175075370"},"id":"CVE-2026-34780-e7b4e66d","signature_type":"Function"},{"digest":{"line_hashes":["163598223645556799758809004922253860728","328782403901881463597991084953359396933","145653381957897113583178423854806299436"],"threshold":0.9},"id":"CVE-2026-34780-f9bf6085","signature_type":"Line","signature_version":"v1","source":"https://github.com/electron/electron/commit/69c8cbf259da0f84e9c1db04958516a68f7170aa","target":{"file":"shell/browser/electron_permission_manager.cc"},"deprecated":false}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34780.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}