PT-2026-102977 · Electron · Electron
CVE-2026-102672
·
Published
2026-09-29
·
Updated
2026-09-29
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Electron versions prior to 42.0.0-beta.2
Electron versions prior to 41.10.5
Electron versions prior to 39.8.10
Description
On macOS, the Squirrel.Mac auto-update framework bundled with Electron includes a privileged
ShipIt helper that executes the final update step with root privileges. A local attacker can exploit a race condition to force this helper to overwrite files of a different application as root, rather than the application that initiated the update. This issue only affects applications on macOS that utilize Squirrel.Mac-based auto-updates.Recommendations
Update to version 42.0.0-beta.2 or later.
Update to version 41.10.5 or later.
Update to version 39.8.10 or later.
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Electron