CVE-2026-70604
- EPSS 0.21%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 05.08.2026 19:17:39
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered with supportFetchAPI: true but without corsEnabled: true was not subject ...
CVE-2026-70605
- EPSS 0.2%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 06.08.2026 15:17:26
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict which schemes a ...
CVE-2026-70606
- EPSS 0.16%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 05.08.2026 18:17:15
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0, when a custom protocol handler returned a ProtocolResponse with a url and no session, Electron made ...
CVE-2026-70599
- EPSS 0.14%
- Veröffentlicht 05.08.2026 16:17:03
- Zuletzt bearbeitet 05.08.2026 19:17:38
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level frame origin ...
CVE-2026-70598
- EPSS 0.1%
- Veröffentlicht 05.08.2026 16:17:03
- Zuletzt bearbeitet 05.08.2026 19:17:38
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully validated by the m...
CVE-2026-70597
- EPSS 0.08%
- Veröffentlicht 05.08.2026 15:21:11
- Zuletzt bearbeitet 06.08.2026 05:17:07
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses on macOS to confirm it was launched by a same-signed parent process co...
CVE-2026-54257
- EPSS 0.25%
- Veröffentlicht 23.06.2026 17:08:31
- Zuletzt bearbeitet 25.06.2026 20:18:11
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 until 42.3.3, Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow. Most apps will crash and som...
CVE-2026-34781
- EPSS 0.14%
- Veröffentlicht 07.04.2026 21:20:12
- Zuletzt bearbeitet 24.07.2026 22:10:00
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that call clipboard.readImage() may be vulnerable to a denial of service. If the system ...
CVE-2026-34765
- EPSS 0.3%
- Veröffentlicht 07.04.2026 21:18:35
- Zuletzt bearbeitet 24.07.2026 22:10:00
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the ...
CVE-2026-34764
- EPSS 0.1%
- Veröffentlicht 06.04.2026 15:46:40
- Zuletzt bearbeitet 01.05.2026 20:01:12
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alpha.1 to before 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that use offscreen rendering with GPU shared textures may be vulner...