6.6

CVE-2026-70602

Electron: Extension tab APIs operate across session boundaries

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session. Apps are only affected if they load Chrome extensions via session.loadExtension and rely on separate sessions to isolate that extension from other content. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Electronjs ≫ Electron SwPlatform node.js Version < 39.8.8
Electronjs ≫ Electron SwPlatform node.js Version >= 40.0.0 < 40.9.0
Electronjs ≫ Electron SwPlatform node.js Version >= 41.0.0 < 41.2.1
Electronjs ≫ Electron Version 42.0.0 Update alpha1 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update alpha2 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update alpha3 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update alpha4 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update alpha5 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update alpha6 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update beta1 SwPlatform node.js
Electronjs ≫ Electron Version 42.0.0 Update beta2 SwPlatform node.js
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.057
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 6.6 1.3 4.7
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://github.com/electron/electron/security/advisories/GHSA-m55f-7gqj-fr98
Vendor Advisory