PT-2026-68206 · Electron · Electron

CVE-2026-70601

·

Published

2026-07-28

·

Updated

2026-08-05

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Electron versions prior to 39.8.9 Electron versions prior to 40.9.2 Electron versions prior to 41.2.2 Electron versions prior to 42.0.0-beta.5
Description Applications that expose Promise-returning functions to web content via the contextBridge may be subject to a context isolation bypass. This allows untrusted web content to gain access to the isolated preload world and all capabilities assigned to the preload script. In renderers where a sandbox is not used or where nodeIntegration is enabled, this can lead to unauthorized Node.js access. This issue specifically affects applications that use contextBridge to wrap ipcRenderer.invoke in windows that load untrusted content.
Recommendations Update to version 39.8.9. Update to version 40.9.2. Update to version 41.2.2. Update to version 42.0.0-beta.5.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11216
CVE-2026-70601
GHSA-H7RP-CF8H-J98X

Affected Products

Electron