CVE-2026-70610Medium· 5.4▾ SunlitElectron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could car…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
0.4% → 0.5%
Last analysed / modified upstream
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry an attacker-influenced prototype, enabling prototype-pollution-style attacks against preload code despite context isolation being enabled. Apps are only affected if their preload code accepts object arguments from untrusted content and reads properties from them without own-property checks, while apps that only accept primitive arguments or validate object arguments are not affected. This issue is fixed in 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
electron < 39.8.9electron >= 40.0.0-alpha.1, < 40.9.2electron >= 41.0.0-alpha.1, < 41.2.2electron >= 42.0.0-alpha.1, < 42.0.0-beta.4Patched in:
electron 39.8.9electron 40.9.2electron 41.2.2electron 42.0.0-beta.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-70611Medium· 6.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70612Medium· 5.4Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70608High· 7.2Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70609Medium· 5.7Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70603Medium· 6.0Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-70602Medium· 6.6Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS