CVE-2026-70607
- EPSS 0.34%
- Veröffentlicht 05.08.2026 16:24:11
- Zuletzt bearbeitet 08.10.2026 13:53:43
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, some window options supplied by web content in the window.open() features string were applied ...
CVE-2026-70606
- EPSS 0.16%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 08.10.2026 13:53:45
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0, when a custom protocol handler returned a ProtocolResponse with a url and no session, Electron made ...
CVE-2026-70605
- EPSS 0.2%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 08.10.2026 13:53:48
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, net.fetch() and net.request() did not restrict which schemes a ...
CVE-2026-70604
- EPSS 0.21%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 08.10.2026 13:53:51
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered with supportFetchAPI: true but without corsEnabled: true was not subject ...
- EPSS 0.1%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 08.10.2026 13:54:00
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that perform string...
CVE-2026-70602
- EPSS 0.16%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 08.10.2026 13:54:05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting APIs were not scoped to the extension's own session. A malicious o...
CVE-2026-70601
- EPSS 0.19%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 08.10.2026 13:54:09
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may be vulnerabl...
CVE-2026-70600
- EPSS 0.14%
- Veröffentlicht 05.08.2026 16:17:04
- Zuletzt bearbeitet 08.10.2026 13:54:11
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside that iframe's b...
CVE-2026-70599
- EPSS 0.14%
- Veröffentlicht 05.08.2026 16:17:03
- Zuletzt bearbeitet 08.10.2026 13:54:19
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level frame origin ...
CVE-2026-70598
- EPSS 0.1%
- Veröffentlicht 05.08.2026 16:17:03
- Zuletzt bearbeitet 08.10.2026 13:54:22
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data received from the GPU process was not fully validated by the m...