CVE-2026-70612
- EPSS 0.36%
- Veröffentlicht 05.08.2026 17:56:41
- Zuletzt bearbeitet 05.08.2026 20:17:17
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbox restricti...
CVE-2026-70611
- EPSS 0.13%
- Veröffentlicht 05.08.2026 17:49:09
- Zuletzt bearbeitet 06.08.2026 05:17:09
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather than reveal it....
CVE-2026-70610
- EPSS 0.38%
- Veröffentlicht 05.08.2026 17:41:03
- Zuletzt bearbeitet 06.08.2026 15:17:27
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry an attacke...
CVE-2026-70609
- EPSS 0.32%
- Veröffentlicht 05.08.2026 17:32:21
- Zuletzt bearbeitet 06.08.2026 05:17:09
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the DevTools fro...
CVE-2026-70608
- EPSS 0.26%
- Veröffentlicht 05.08.2026 17:27:15
- Zuletzt bearbeitet 05.08.2026 19:17:40
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger setWindowOpenH...
CVE-2026-70607
- EPSS 0.34%
- Veröffentlicht 05.08.2026 16:24:11
- Zuletzt bearbeitet 05.08.2026 19:17:39
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, some window options supplied by web content in the window.open() features string were applied ...
- EPSS 0.1%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 06.08.2026 05:17:08
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that perform string...
CVE-2026-70600
- EPSS 0.14%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 06.08.2026 15:17:26
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside that iframe's b...
CVE-2026-70601
- EPSS 0.19%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 05.08.2026 18:17:14
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may be vulnerabl...
CVE-2026-70602
- EPSS 0.16%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 05.08.2026 17:16:54
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. A malicious o...