CVE-2026-34778: Electron: Service worker can spoof executeJavaScript IPC replies
Impact A service worker running in a session could spoof reply messages on the internal IPC channel used by webContents.executeJavaScript() and related methods, causing the main-process promise to resolve with attacker-controlled data.
Apps are only affected if they have service workers registered and use the result of webContents.executeJavaScript() (or webFrameMain.executeJavaScript()) in security-sensitive decisions.
Workarounds Do not trust the return value of webContents.executeJavaScript() for security decisions. Use dedicated, validated IPC channels for security-relevant communication with renderers.
Fixed Versions 41.0.0 40.8.1 39.8.1 38.8.6
For more information If there are any questions or comments about this advisory, please email security@electronjs.org
Other sources
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, a service worker running in a session could spoof reply messages on the internal IPC channel used by webContents.executeJavaScript() and related methods, causing the main-process promise to resolve with attacker-controlled data. Apps are only affected if they have service workers registered and use the result of webContents.executeJavaScript() (or webFrameMain.executeJavaScript()) in security-sensitive decisions. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 41.0.0 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 40.8.1 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 39.8.1 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 38.8.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 38.8.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 39.8.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 40.8.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 41.0.0 - Configuration
Update security-sensitive logic to not rely on the (possibly spoofed) return value from webContents.executeJavaScript() (or webFrameMain.executeJavaScript()).
Electron (app code using webContents.executeJavaScript/webFrameMain.executeJavaScript) Security handling of executeJavaScript return value = Do not trust the return value of webContents.executeJavaScript() for security decisions - Compensating control
Use dedicated, validated IPC channels for security-relevant communication with renderers.