PT-2026-68207 · Electron · Electron

CVE-2026-70602

·

Published

2026-08-05

·

Updated

2026-08-05

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Electron versions prior to 39.8.8 Electron versions prior to 40.9.0 Electron versions prior to 41.2.1 Electron versions prior to 42.0.0-beta.3
Description Extension tab and scripting APIs were not scoped to the extension's own session. This allows a malicious or compromised extension loaded into one session to navigate, script, and read from windows belonging to a different session. This issue specifically affects applications that load Chrome extensions via the session.loadExtension function and rely on separate sessions to isolate those extensions from other content.
Recommendations Update to version 39.8.8. Update to version 40.9.0. Update to version 41.2.1. Update to version 42.0.0-beta.3. Only load extensions from trusted sources and do not rely solely on session separation to contain an extension.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70602
GHSA-M55F-7GQJ-FR98

Affected Products

Electron