PT-2026-68207 · Electron · Electron
CVE-2026-70602
·
Published
2026-08-05
·
Updated
2026-08-05
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Electron versions prior to 39.8.8
Electron versions prior to 40.9.0
Electron versions prior to 41.2.1
Electron versions prior to 42.0.0-beta.3
Description
Extension tab and scripting APIs were not scoped to the extension's own
session. This allows a malicious or compromised extension loaded into one session to navigate, script, and read from windows belonging to a different session. This issue specifically affects applications that load Chrome extensions via the session.loadExtension function and rely on separate sessions to isolate those extensions from other content.Recommendations
Update to version 39.8.8.
Update to version 40.9.0.
Update to version 41.2.1.
Update to version 42.0.0-beta.3.
Only load extensions from trusted sources and do not rely solely on session separation to contain an extension.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Electron