PT-2026-102977 · Electron · Electron

CVE-2026-102672

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Electron versions prior to 42.0.0-beta.2 Electron versions prior to 41.10.5 Electron versions prior to 39.8.10
Description On macOS, the Squirrel.Mac auto-update framework bundled with Electron includes a privileged ShipIt helper that executes the final update step with root privileges. A local attacker can exploit a race condition to force this helper to overwrite files of a different application as root, rather than the application that initiated the update. This issue only affects applications on macOS that utilize Squirrel.Mac-based auto-updates.
Recommendations Update to version 42.0.0-beta.2 or later. Update to version 41.10.5 or later. Update to version 39.8.10 or later.

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102672
GHSA-VV43-5JGX-7QV8

Affected Products

Electron