CVE-2026-102675High· 7.4▾ TwilightElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpP…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI enabled but corsEnabled disabled could remain script-readable across origins. This residual issue completes the remediation for CVE-2026-70604. Applications are affected only when they expose such a scheme and load untrusted content in the same session. Schemes intentionally registered with corsEnabled enabled remain cross-origin readable by design. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
electron < 41.10.6electron >= 42.0.0-alpha.1, < 42.9.2electron >= 43.0.0-alpha.1, < 43.4.1electron >= 44.0.0-alpha.1, < 44.0.0-beta.5Patched in:
electron 41.10.6electron 42.9.2electron 43.4.1electron 44.0.0-beta.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102676High· 8.3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-102674High· 8.2Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-102673High· 8.2Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70599Medium· 5.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-102677High· 7.8Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-102672Medium· 6.7Electron: Local race condition in Squirrel.Mac update installation on macOS