These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-70612 is a medium-severity vulnerability in Electron, a framework for writing cross-platform desktop applications using JavaScript, HTML, and CSS. The issue allows a sandboxed iframe to launch an OS-registered external application when a request to open an external protocol URL is made from web content, bypassing iframe sandbox restrictions. This vulnerability affects applications that render unt [truncated]
CVE-2026-70610 is a vulnerability in Electron, a framework for writing cross-platform desktop applications using JavaScript, HTML, and CSS. The vulnerability allows objects copied across the contextBridge boundary from untrusted content to carry an attacker-influenced prototype, enabling prototype-pollution-style attacks against preload code despite context isolation being enabled. This issue is fixed in [truncated]
CVE-2026-70609 is a vulnerability in the Electron framework's DevTools context. An attacker could exploit this vulnerability to execute script in the DevTools context, potentially leading to elevated privileges in unsandboxed configurations. Electron application developers and maintainers should assess exposure, verify affected versions, and update to fixed versions to mitigate potential risks. The issue [truncated]
CVE-2026-70608 Electron Sandbox Bypass. The Electron framework vulnerability allows sandboxed iframes to bypass restrictions and open new windows without user interaction. This issue affects applications embedding untrusted content in sandboxed iframes without the allow-popups keyword. Fixes are available in Electron versions 39.8.10, 41.10.3, and 42.0.1. Developers and security teams using Electron shoul [truncated]
CVE-2026-70607 Electron Framework Vulnerability Debrief. The Electron framework, used for building cross-platform desktop applications, had a vulnerability where certain window options supplied by web content in the window.open() features string were applied to the new BrowserWindow without an allowlist. This could allow untrusted content to set window options it should not control, potentially leading to [truncated]
CVE-2026-70606 Electron ProtocolResponse URL Session Isolation Bypass. Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML, and CSS. A custom protocol handler could return a ProtocolResponse with a URL and no session, allowing cached responses to be reused across isolated session partitions in Electron versions prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0. This i [truncated]
CVE-2026-70605 debrief based on CVE Program and NVD records. The Electron framework vulnerability allows redirect attacks, potentially disclosing local file contents. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed. Apps are o [truncated]
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML, and CSS. A vulnerability in custom schemes registered with supportFetchAPI: true but without corsEnabled: true allows cross-origin data exposure in Electron versions prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0. This issue can be mitigated by updating Electron to a secure version, assessing applications using c [truncated]
CVE-2026-70603 is a medium-severity vulnerability in Electron, a framework for writing cross-platform desktop applications. The vulnerability affects versions prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1. An attacker could exploit this vulnerability by providing a path containing embedded null bytes to the shell.openPath() function, potentially bypassing string-only validation of file paths.
A vulnerability in Electron, a framework for writing cross-platform desktop applications, allows a malicious or compromised extension loaded into one session to navigate, script, and read from windows belonging to a different session. This issue affects apps that load Chrome extensions via session.loadExtension and rely on separate sessions to isolate that extension from other content.
CVE-2026-70601 Electron Context Isolation Bypass. Electron apps using contextBridge to expose Promise-returning functions to untrusted web content are vulnerable to context isolation bypass. This could allow untrusted web content to access the isolated preload world and its capabilities. In certain configurations, like renderers without a sandbox or with nodeIntegration enabled, this could escalate to Nod [truncated]
A local process can bypass the check Electron uses on macOS to confirm it was launched by a same-signed parent process, potentially running code inside a signed app with its TCC permissions and keychain access. This bypass can occur because Electron's security check on macOS does not correctly validate the parent process signature, allowing a local attacker to exploit this vulnerability. The issue is part [truncated]
CVE-2026-34781 is a denial of service vulnerability in Electron, a framework for writing cross-platform desktop applications using JavaScript, HTML, and CSS. Apps that call clipboard.readImage() may be vulnerable if the system clipboard contains image data that fails to decode, triggering a controlled abort and crashing the process. This issue does not allow memory corruption or code execution. The vulner [truncated]
CVE-2026-34765 is a medium-severity vulnerability in Electron, a framework for writing cross-platform desktop applications using JavaScript, HTML, and CSS. The vulnerability occurs when a renderer calls window.open() with a target name, and Electron does not correctly scope the named-window lookup to the opener's browsing context group. This oversight allows a renderer to navigate an existing child window [truncated]
Electron, a framework for building cross-platform desktop applications, had a vulnerability where the origin passed to session.setPermissionRequestHandler() was incorrectly set to the top-level page's origin instead of the requesting iframe's origin. This could lead to unintended permission grants to embedded third-party content. The issue has been patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0. D [truncated]
CVE-2026-34774 is a high-severity use-after-free vulnerability in Electron, a framework for building cross-platform desktop applications. The vulnerability affects applications that use offscreen rendering and allow child windows via window.open(). If the parent offscreen WebContents is destroyed while a child window remains open, subsequent paint frames on the child may dereference freed memory, potentia [truncated]
CVE-2026-34773 is a medium-severity vulnerability in the Electron framework that allows protocol handler hijacking on Windows systems. The vulnerability exists in the app.setAsDefaultProtocolClient() function, which did not validate the protocol name before writing to the registry. This allows an attacker to write to arbitrary subkeys under HKCUSoftwareClasses, potentially hijacking existing protocol hand [truncated]
CVE-2026-34767 is a vulnerability in Electron, a framework for writing cross-platform desktop applications, that allows for HTTP response header injection. This vulnerability affects Electron versions prior to 38.8.6, 39.8.3, 40.8.3, and 41.0.3. An attacker who can influence a header value may be able to inject additional response headers, affecting cookies, content security policy, or cross-origin access [truncated]
The Electron framework, used for building cross-platform desktop applications, had a security vulnerability. An issue was found in the select-usb-device event callback where it did not validate the chosen device ID against the filtered list presented to the handler. This could allow an app to gain access to a device that did not match the renderer's requested filters or was listed in exclusionFilters. How [truncated]