PatchSiren

Electron CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM electron CVE published 2026-08-05

CVE-2026-70612

CVE-2026-70612 is a medium-severity vulnerability in Electron, a framework for writing cross-platform desktop applications using JavaScript, HTML, and CSS. The issue allows a sandboxed iframe to launch an OS-registered external application when a request to open an external protocol URL is made from web content, bypassing iframe sandbox restrictions. This vulnerability affects applications that render unt [truncated]

MEDIUM electron CVE published 2026-08-05

CVE-2026-70610

CVE-2026-70610 is a vulnerability in Electron, a framework for writing cross-platform desktop applications using JavaScript, HTML, and CSS. The vulnerability allows objects copied across the contextBridge boundary from untrusted content to carry an attacker-influenced prototype, enabling prototype-pollution-style attacks against preload code despite context isolation being enabled. This issue is fixed in [truncated]

MEDIUM electron CVE published 2026-08-05

CVE-2026-70609

CVE-2026-70609 is a vulnerability in the Electron framework's DevTools context. An attacker could exploit this vulnerability to execute script in the DevTools context, potentially leading to elevated privileges in unsandboxed configurations. Electron application developers and maintainers should assess exposure, verify affected versions, and update to fixed versions to mitigate potential risks. The issue [truncated]

HIGH electron CVE published 2026-08-05

CVE-2026-70608

CVE-2026-70608 Electron Sandbox Bypass. The Electron framework vulnerability allows sandboxed iframes to bypass restrictions and open new windows without user interaction. This issue affects applications embedding untrusted content in sandboxed iframes without the allow-popups keyword. Fixes are available in Electron versions 39.8.10, 41.10.3, and 42.0.1. Developers and security teams using Electron shoul [truncated]

MEDIUM electron CVE published 2026-08-05

CVE-2026-70607

CVE-2026-70607 Electron Framework Vulnerability Debrief. The Electron framework, used for building cross-platform desktop applications, had a vulnerability where certain window options supplied by web content in the window.open() features string were applied to the new BrowserWindow without an allowlist. This could allow untrusted content to set window options it should not control, potentially leading to [truncated]

MEDIUM electron CVE published 2026-08-05

CVE-2026-70606

CVE-2026-70606 Electron ProtocolResponse URL Session Isolation Bypass. Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML, and CSS. A custom protocol handler could return a ProtocolResponse with a URL and no session, allowing cached responses to be reused across isolated session partitions in Electron versions prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0. This i [truncated]

MEDIUM electron CVE published 2026-08-05

CVE-2026-70605

CVE-2026-70605 debrief based on CVE Program and NVD records. The Electron framework vulnerability allows redirect attacks, potentially disclosing local file contents. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed. Apps are o [truncated]

HIGH electron CVE published 2026-08-05

CVE-2026-70604

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML, and CSS. A vulnerability in custom schemes registered with supportFetchAPI: true but without corsEnabled: true allows cross-origin data exposure in Electron versions prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0. This issue can be mitigated by updating Electron to a secure version, assessing applications using c [truncated]

MEDIUM electron CVE published 2026-08-05

CVE-2026-70603

CVE-2026-70603 is a medium-severity vulnerability in Electron, a framework for writing cross-platform desktop applications. The vulnerability affects versions prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1. An attacker could exploit this vulnerability by providing a path containing embedded null bytes to the shell.openPath() function, potentially bypassing string-only validation of file paths.

MEDIUM electron CVE published 2026-08-05

CVE-2026-70602

A vulnerability in Electron, a framework for writing cross-platform desktop applications, allows a malicious or compromised extension loaded into one session to navigate, script, and read from windows belonging to a different session. This issue affects apps that load Chrome extensions via session.loadExtension and rely on separate sessions to isolate that extension from other content.

HIGH electron CVE published 2026-08-05

CVE-2026-70601

CVE-2026-70601 Electron Context Isolation Bypass. Electron apps using contextBridge to expose Promise-returning functions to untrusted web content are vulnerable to context isolation bypass. This could allow untrusted web content to access the isolated preload world and its capabilities. In certain configurations, like renderers without a sandbox or with nodeIntegration enabled, this could escalate to Nod [truncated]

MEDIUM electron CVE published 2026-08-05

CVE-2026-70597

A local process can bypass the check Electron uses on macOS to confirm it was launched by a same-signed parent process, potentially running code inside a signed app with its TCC permissions and keychain access. This bypass can occur because Electron's security check on macOS does not correctly validate the parent process signature, allowing a local attacker to exploit this vulnerability. The issue is part [truncated]

LOW electron CVE published 2026-04-07

CVE-2026-34781

CVE-2026-34781 is a denial of service vulnerability in Electron, a framework for writing cross-platform desktop applications using JavaScript, HTML, and CSS. Apps that call clipboard.readImage() may be vulnerable if the system clipboard contains image data that fails to decode, triggering a controlled abort and crashing the process. This issue does not allow memory corruption or code execution. The vulner [truncated]

MEDIUM electron CVE published 2026-04-07

CVE-2026-34765

CVE-2026-34765 is a medium-severity vulnerability in Electron, a framework for writing cross-platform desktop applications using JavaScript, HTML, and CSS. The vulnerability occurs when a renderer calls window.open() with a target name, and Electron does not correctly scope the named-window lookup to the opener's browsing context group. This oversight allows a renderer to navigate an existing child window [truncated]

MEDIUM electron CVE published 2026-04-04

CVE-2026-34777

Electron, a framework for building cross-platform desktop applications, had a vulnerability where the origin passed to session.setPermissionRequestHandler() was incorrectly set to the top-level page's origin instead of the requesting iframe's origin. This could lead to unintended permission grants to embedded third-party content. The issue has been patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0. D [truncated]

HIGH electron CVE published 2026-04-04

CVE-2026-34774

CVE-2026-34774 is a high-severity use-after-free vulnerability in Electron, a framework for building cross-platform desktop applications. The vulnerability affects applications that use offscreen rendering and allow child windows via window.open(). If the parent offscreen WebContents is destroyed while a child window remains open, subsequent paint frames on the child may dereference freed memory, potentia [truncated]

MEDIUM electron CVE published 2026-04-04

CVE-2026-34773

CVE-2026-34773 is a medium-severity vulnerability in the Electron framework that allows protocol handler hijacking on Windows systems. The vulnerability exists in the app.setAsDefaultProtocolClient() function, which did not validate the protocol name before writing to the registry. This allows an attacker to write to arbitrary subkeys under HKCUSoftwareClasses, potentially hijacking existing protocol hand [truncated]

MEDIUM electron CVE published 2026-04-04

CVE-2026-34767

CVE-2026-34767 is a vulnerability in Electron, a framework for writing cross-platform desktop applications, that allows for HTTP response header injection. This vulnerability affects Electron versions prior to 38.8.6, 39.8.3, 40.8.3, and 41.0.3. An attacker who can influence a header value may be able to inject additional response headers, affecting cookies, content security policy, or cross-origin access [truncated]

LOW electron CVE published 2026-04-04

CVE-2026-34766

The Electron framework, used for building cross-platform desktop applications, had a security vulnerability. An issue was found in the select-usb-device event callback where it did not validate the chosen device ID against the filtered list presented to the handler. This could allow an app to gain access to a device that did not match the renderer's requested filters or was listed in exclusionFilters. How [truncated]