CVE-2026-102672Medium· 6.7▾ SunlitElectron: Local race condition in Squirrel.Mac update installation on macOS
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
On macOS, Electron bundles the Squirrel.Mac auto-update framework, whose privileged ShipIt helper performs the final step of an update as root. A local attacker could cause that helper to overwrite a different application's files, as root, instead of the app that started the update. Exploitation requires local access to the machine.
Apps are only affected on macOS if they ship Squirrel.Mac-based auto-updates. Apps on other platforms, or that do not use Squirrel.Mac auto-updates, are not affected.
There are no app side workarounds, you must update to a patched version of Electron.
42.0.0-beta.241.10.539.8.10If you have any questions or comments about this advisory, email us at [email protected]
electron < 39.8.10electron >= 40.0.0-alpha.1, < 41.10.5electron >= 42.0.0-alpha.1, < 42.0.0-beta.2Upgrade to a patched release:
electron 39.8.10electron 41.10.5electron 42.0.0-beta.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-70608High· 7.2Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70597Medium· 6.3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-102677High· 7.8Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-102676High· 8.3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-102674High· 8.2Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-102675High· 7.4Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS