Skip to content

fix: avoid UB in menu.popup with frame from OSR window on macOS - #53362

Merged
dsanders11 merged 1 commit into
44-x-yfrom
manual-bp/dsanders11/pr/53242/branch/44-x-y
Sep 2, 2026
Merged

dsanders11 merged 1 commit into
44-x-yfrom
manual-bp/dsanders11/pr/53242/branch/44-x-y

Conversation

@dsanders11

Copy link
Copy Markdown
Member

Backport of #53242.

See that PR for details.

Notes: Fixed a potential crash when using menu.popup with a frame from an offscreen rendered window

* test: test OSR frame with menu.popup

* fix: avoid UB in menu.popup with frame from OSR window on macOS

Assisted-by: Claude Opus 5
@electron-cation electron-cation Bot added the new-pr 🌱 PR opened recently label Sep 1, 2026
@trop trop Bot added 44-x-y backport This is a backport PR semver/patch backwards-compatible bug fixes labels Sep 1, 2026
@electron-cation electron-cation Bot removed the new-pr 🌱 PR opened recently label Sep 1, 2026
@dsanders11
dsanders11 marked this pull request as ready for review September 1, 2026 22:43

@ckerr ckerr left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, nice cleanup.

Removing the // nogncheck headers is a nice bonus as well.

@dsanders11
dsanders11 merged commit fcfbdf6 into 44-x-y Sep 2, 2026
100 checks passed
@dsanders11
dsanders11 deleted the manual-bp/dsanders11/pr/53242/branch/44-x-y branch September 2, 2026 21:37
@release-clerk

release-clerk Bot commented Sep 2, 2026

Copy link
Copy Markdown

Release Notes Persisted

Fixed a potential crash when using menu.popup with a frame from an offscreen rendered window

@dsanders11

Copy link
Copy Markdown
Member Author

/trop run backport-to 43-x-y

@trop

trop Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

The backport process for this PR has been manually initiated - sending your PR to 43-x-y!

@trop

trop Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

I was unable to backport this PR to "43-x-y" cleanly;
you will need to perform this backport manually.

renovate Bot added a commit to cigaleapp/cigale that referenced this pull request Sep 13, 2026
##### [v44.2.0](https://github.com/electron/electron/releases/tag/v44.2.0)

### Release Notes for v44.2.0

#### Fixes

- Fixed a pending read on a `net.request` chunked upload stream inside a protocol handler never settling when the request failed or was aborted. [#53373](electron/electron#53373) <sup>(Also in [43](electron/electron#53374), [45](https://github.com/electron/electron/pull/53368))</sup>
- Fixed a potential crash when using `menu.popup` with a frame from an offscreen rendered window. [#53362](electron/electron#53362) <sup>(Also in [43](https://github.com/electron/electron/pull/53432))</sup>
- Fixed an intermittent crash (access violation) on Windows when an ASAR integrity violation is detected, so the process now exits with code 1 as intended. [#53455](electron/electron#53455) <sup>(Also in [43](electron/electron#53456), [45](https://github.com/electron/electron/pull/53438))</sup>
- Fixed application crash after a large number of IPC messages from renderers. [#53417](electron/electron#53417) <sup>(Also in [42](electron/electron#53419), [43](electron/electron#53420), [45](https://github.com/electron/electron/pull/53418))</sup>
- Fixed native addons deriving from `node::ObjectWrap` aborting during garbage collection on Node.js 24.19.0 and later. [#53392](electron/electron#53392) <sup>(Also in [42](electron/electron#53394), [43](electron/electron#53393), [45](https://github.com/electron/electron/pull/53391))</sup>

#### Other Changes

- Backported fixes from upstream ANGLE, Chromium, Skia and V8. [#53479](electron/electron#53479)
- Improved throughput of responses that `protocol.handle` handlers return straight from `net.fetch`. [#53378](electron/electron#53378)
- Updated Chromium to 152.0.7977.76. [#53382](electron/electron#53382)
- Updated Node.js to v24.20.0. [#53250](electron/electron#53250)
##### [v44.1.1](https://github.com/electron/electron/releases/tag/v44.1.1)

### Release Notes for v44.1.1

#### Fixes

- Fixed `chrome.tabs.query()` returning tab `url` and `title` to extensions without the `tabs` permission or host access, aligning with `tabs.get`. [#53354](electron/electron#53354) <sup>(Also in [42](electron/electron#53355), [43](electron/electron#53356), [45](https://github.com/electron/electron/pull/53353))</sup>
- Fixed a renderer crash when an array with a throwing property getter is passed across `contextBridge`, and several main/utility-process crashes when option objects passed to Electron APIs contain throwing accessors or Proxy traps. [#53331](electron/electron#53331) <sup>(Also in [42](electron/electron#53329), [43](https://github.com/electron/electron/pull/53330))</sup>
- Fixed an intermittent crash at startup on Linux caused by a race between Pango and the main thread initializing fontconfig. [#53340](electron/electron#53340) <sup>(Also in [43](electron/electron#53339), [45](https://github.com/electron/electron/pull/53338))</sup>
- Fixed an issue where an exception thrown by a property getter on an object passed through `contextBridge` was swallowed instead of being thrown back to the caller. [#53335](electron/electron#53335) <sup>(Also in [43](electron/electron#53334), [45](https://github.com/electron/electron/pull/53297))</sup>
- Fixed main process crashes when navigating to `http://accessibility/` or `http://devtools/`, when an extension background page used `navigator.mediaDevices`, and when calling `SerialPort.forget()` for a disconnected device. [#53333](electron/electron#53333) <sup>(Also in [43](electron/electron#53332), [45](https://github.com/electron/electron/pull/53325))</sup>
- Fixed the PDF viewer failing to save an edited PDF with `NotAllowedError: Third party iframes are not allowed to show a file picker`. [#53328](electron/electron#53328) <sup>(Also in [43](electron/electron#53327), [45](https://github.com/electron/electron/pull/53326))</sup>
gwennlbh pushed a commit to cigaleapp/cigale that referenced this pull request Sep 14, 2026
##### [v44.2.0](https://github.com/electron/electron/releases/tag/v44.2.0)

### Release Notes for v44.2.0

#### Fixes

- Fixed a pending read on a `net.request` chunked upload stream inside a protocol handler never settling when the request failed or was aborted. [#53373](electron/electron#53373) <sup>(Also in [43](electron/electron#53374), [45](https://github.com/electron/electron/pull/53368))</sup>
- Fixed a potential crash when using `menu.popup` with a frame from an offscreen rendered window. [#53362](electron/electron#53362) <sup>(Also in [43](https://github.com/electron/electron/pull/53432))</sup>
- Fixed an intermittent crash (access violation) on Windows when an ASAR integrity violation is detected, so the process now exits with code 1 as intended. [#53455](electron/electron#53455) <sup>(Also in [43](electron/electron#53456), [45](https://github.com/electron/electron/pull/53438))</sup>
- Fixed application crash after a large number of IPC messages from renderers. [#53417](electron/electron#53417) <sup>(Also in [42](electron/electron#53419), [43](electron/electron#53420), [45](https://github.com/electron/electron/pull/53418))</sup>
- Fixed native addons deriving from `node::ObjectWrap` aborting during garbage collection on Node.js 24.19.0 and later. [#53392](electron/electron#53392) <sup>(Also in [42](electron/electron#53394), [43](electron/electron#53393), [45](https://github.com/electron/electron/pull/53391))</sup>

#### Other Changes

- Backported fixes from upstream ANGLE, Chromium, Skia and V8. [#53479](electron/electron#53479)
- Improved throughput of responses that `protocol.handle` handlers return straight from `net.fetch`. [#53378](electron/electron#53378)
- Updated Chromium to 152.0.7977.76. [#53382](electron/electron#53382)
- Updated Node.js to v24.20.0. [#53250](electron/electron#53250)
##### [v44.1.1](https://github.com/electron/electron/releases/tag/v44.1.1)

### Release Notes for v44.1.1

#### Fixes

- Fixed `chrome.tabs.query()` returning tab `url` and `title` to extensions without the `tabs` permission or host access, aligning with `tabs.get`. [#53354](electron/electron#53354) <sup>(Also in [42](electron/electron#53355), [43](electron/electron#53356), [45](https://github.com/electron/electron/pull/53353))</sup>
- Fixed a renderer crash when an array with a throwing property getter is passed across `contextBridge`, and several main/utility-process crashes when option objects passed to Electron APIs contain throwing accessors or Proxy traps. [#53331](electron/electron#53331) <sup>(Also in [42](electron/electron#53329), [43](https://github.com/electron/electron/pull/53330))</sup>
- Fixed an intermittent crash at startup on Linux caused by a race between Pango and the main thread initializing fontconfig. [#53340](electron/electron#53340) <sup>(Also in [43](electron/electron#53339), [45](https://github.com/electron/electron/pull/53338))</sup>
- Fixed an issue where an exception thrown by a property getter on an object passed through `contextBridge` was swallowed instead of being thrown back to the caller. [#53335](electron/electron#53335) <sup>(Also in [43](electron/electron#53334), [45](https://github.com/electron/electron/pull/53297))</sup>
- Fixed main process crashes when navigating to `http://accessibility/` or `http://devtools/`, when an extension background page used `navigator.mediaDevices`, and when calling `SerialPort.forget()` for a disconnected device. [#53333](electron/electron#53333) <sup>(Also in [43](electron/electron#53332), [45](https://github.com/electron/electron/pull/53325))</sup>
- Fixed the PDF viewer failing to save an edited PDF with `NotAllowedError: Third party iframes are not allowed to show a file picker`. [#53328](electron/electron#53328) <sup>(Also in [43](electron/electron#53327), [45](https://github.com/electron/electron/pull/53326))</sup>

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

44-x-y backport This is a backport PR semver/patch backwards-compatible bug fixes

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

2 participants

Sponsor
SponsoredKunjungi sekarang
Promo