CVE-2026-70602

MEDIUM

Electron: Extension tab APIs operate across session boundaries

Title source: cna
STIX 2.1

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session. Apps are only affected if they load Chrome extensions via session.loadExtension and rely on separate sessions to isolate that extension from other content. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.

References (1)

Core 1
Core References

Scores

CVSS v3 6.6
EPSS 0.0016
EPSS Percentile 5.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (8)
electron/electron < 39.8.8
electron/electron >= 40.0.0-alpha.1, < 40.9.0
electron/electron >= 41.0.0-alpha.1, < 41.2.1
electron/electron >= 42.0.0-alpha.1, < 42.0.0-beta.3
npm/electron 0 - 39.8.8npm
npm/electron 40.0.0-alpha.1 - 40.9.0npm
npm/electron 41.0.0-alpha.1 - 41.2.1npm
npm/electron 42.0.0-alpha.1 - 42.0.0-beta.3npm
Published Aug 05, 2026
Tracked Since Aug 05, 2026