PT-2026-102756 · Electron · Electron
CVSS v3.1
7.8
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Electron versions 42.3.3 through 42.9.9
Electron versions 43.0.0 through 43.4.9
Electron versions 44.0.0-beta.0 through 44.0.0-beta.5
Description
The sandboxed preload code cache fails to verify that a cached entry matches the preload it was served for. This allows a compromised renderer to write attacker-controlled cache data, which Electron may then reuse during a subsequent load. This process enables the execution of renderer code within the more privileged preload context. This issue specifically affects applications that load untrusted content.
Recommendations
Update to version 42.10.0.
Update to version 43.5.0.
Update to version 44.0.0-beta.6.
Exploit
Fix
Insufficient Verification of Data Authenticity
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Electron