{"id":"CVE-2026-102672","aliases":["GHSA-vv43-5jgx-7qv8"],"title":"Electron: Local race condition in Squirrel.Mac update installation on macOS","summary":"Electron: Local race condition in Squirrel.Mac update installation on macOS","severity":"medium","cvss":6.7,"cwe":["CWE-367"],"vendor":"electron","product":"electron","ecosystem":"npm","affected":["electron < 39.8.10","electron >= 40.0.0-alpha.1, < 41.10.5","electron >= 42.0.0-alpha.1, < 42.0.0-beta.2"],"patched":["electron 39.8.10","electron 41.10.5","electron 42.0.0-beta.2"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T18:07:01Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-vv43-5jgx-7qv8","references":[{"url":"https://github.com/electron/electron/security/advisories/GHSA-vv43-5jgx-7qv8"},{"url":"https://github.com/electron/electron/pull/50745"},{"url":"https://github.com/electron/electron/commit/01faabfc250801a980fc94d64608046c67fc1cd9"},{"url":"https://github.com/electron/electron/commit/15e2928a5c5f01759107b414010e220d90d59cef"},{"url":"https://github.com/electron/electron/commit/a0f9ff4cc0340545008424232d49caadd9c0c767"},{"url":"https://github.com/electron/electron/commit/b8f25c4cedb2e0f5f475912b709aba19c57c26be"},{"url":"https://github.com/electron/electron/releases/tag/v39.8.10"},{"url":"https://github.com/electron/electron/releases/tag/v41.10.5"},{"url":"https://github.com/electron/electron/releases/tag/v42.0.0-beta.2"},{"url":"https://github.com/advisories/GHSA-vv43-5jgx-7qv8"}],"tags":["ghsa","npm"],"ingestedAt":"2026-09-29T18:42:35.832Z","slug":"CVE-2026-102672","body":"## Overview\n\n### Impact\n\nOn macOS, Electron bundles the Squirrel.Mac auto-update framework, whose privileged `ShipIt` helper performs the final step of an update as root. A local attacker could cause that helper to overwrite a different application's files, as root, instead of the app that started the update. Exploitation requires local access to the machine.\n\nApps are only affected on macOS if they ship Squirrel.Mac-based auto-updates. Apps on other platforms, or that do not use Squirrel.Mac auto-updates, are not affected.\n\n### Workarounds\n\nThere are no app side workarounds, you must update to a patched version of Electron.\n\n### Fixed Versions\n\n* `42.0.0-beta.2`\n* `41.10.5`\n* `39.8.10`\n\n### For more information\n\nIf you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org)\n\n## Affected packages\n\n- `electron < 39.8.10`\n- `electron >= 40.0.0-alpha.1, < 41.10.5`\n- `electron >= 42.0.0-alpha.1, < 42.0.0-beta.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `electron 39.8.10`\n- `electron 41.10.5`\n- `electron 42.0.0-beta.2`","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":36.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}