PT-2026-102756 · Electron · Electron

·

CVE-2026-102677

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Electron versions 42.3.3 through 42.9.9 Electron versions 43.0.0 through 43.4.9 Electron versions 44.0.0-beta.0 through 44.0.0-beta.5
Description The sandboxed preload code cache fails to verify that a cached entry matches the preload it was served for. This allows a compromised renderer to write attacker-controlled cache data, which Electron may then reuse during a subsequent load. This process enables the execution of renderer code within the more privileged preload context. This issue specifically affects applications that load untrusted content.
Recommendations Update to version 42.10.0. Update to version 43.5.0. Update to version 44.0.0-beta.6.

Exploit

Fix

Insufficient Verification of Data Authenticity

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102677
GHSA-QMV3-FV6V-RMHQ

Affected Products

Electron