CVE-2026-70601High· 7.5▾ TwilightElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
0.2% → 0.2%
Last analysed / modified upstream
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may be vulnerable to a context isolation bypass. Untrusted web content could obtain access to the isolated preload world and, through it, every capability the preload script has. In renderers without a sandbox, or with nodeIntegration enabled, this may escalate to Node.js access. Apps are affected if they expose Promise-returning functions via contextBridge, the standard pattern for wrapping ipcRenderer.invoke, in windows that load untrusted content. This issue is fixed in versions 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
electron < 39.8.9electron >= 40.0.0-alpha.1, < 40.9.2electron >= 41.0.0-alpha.1, < 41.2.2electron >= 42.0.0-alpha.1, < 42.0.0-beta.5Patched in:
electron 39.8.9electron 40.9.2electron 41.2.2electron 42.0.0-beta.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-70608High· 7.2Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70612Medium· 5.4Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70609Medium· 5.7Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70610Medium· 5.4Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70611Medium· 6.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70603Medium· 6.0Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS