Multiple security vulnerabilities have been identified in electron, a product used for building cross-platform desktop applications. These vulnerabilities pose a risk of exploitation by attackers, potentially leading to code execution and data theft. The affected version range is not explicitly stated in the article.
CVE-2026-70597 (CVSS 7.5 — High Severity): A parent process code-sign check spoofing vulnerability exists in electron, allowing an attacker to execute malicious code. An attacker with capability can exploit this vulnerability by spoofing the code-sign check.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in electron, a product used for building cross-platform desktop applications. These vulnerabilities pose a risk of exploitation by attackers, potentially leading to code execution and data theft. The affected version range is not explicitly stated in the article.
CVE-2026-70597 (CVSS 7.5 — High Severity): A parent process code-sign check spoofing vulnerability exists in electron, allowing an attacker to execute malicious code. An attacker with capability can exploit this vulnerability by spoofing the code-sign check.[emaillocker id="1283"]
CVE-2026-70598: Electron's off-screen rendering trusts GPU-supplied geometry over shared-memory size, potentially leading to a security vulnerability.
CVE-2026-70599 (CVSS 7.5 — High Severity): A permission check handler receives the main frame origin instead of requesting the iframe origin in electron, allowing an attacker to bypass permission checks.
CVE-2026-70600: An Electron cross-origin iframe can position a native autofill popup, potentially leading to a security vulnerability.
CVE-2026-70601 (CVSS 7.5 — High Severity): Electron's context isolation bypass via Function.prototype.bind hijack allows an attacker with capability to execute malicious code.
CVE-2026-70603 (CVSS 7.5 — High Severity): Electron's shell.openPath path validation bypass via embedded null byte allows an attacker with capability to execute malicious code.
CVE-2026-70602: Extension tab APIs operate across session boundaries in electron, potentially leading to a security vulnerability.
CVE-2026-70604: A custom protocol with supportFetchAPI but not corsEnabled in electron allows cross-origin reads, potentially leading to a security vulnerability.
CVE-2026-70605 (CVSS 7.5 — High Severity): Electron's HTTP redirect followed into local file loader allows an attacker with capability to execute malicious code.
CVE-2026-70606: ProtocolResponse.url reuses the default session cache instead of the registering session in electron, potentially leading to a security vulnerability.
CVE-2026-70607 (CVSS 7.5 — High Severity): Electron's window.open features string controls some window options considered privileged, allowing an attacker with capability to execute malicious code.
CVE-2026-70608: A sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path in electron, potentially leading to a security vulnerability.
CVE-2026-70609 (CVSS 7.5 — High Severity): Electron's DevTools JavaScript Injection via Unsanitized Dock State Parameter allows an attacker with capability to execute malicious code.
CVE-2026-70610: The contextBridge object copy honors prototype setters in electron, potentially leading to a security vulnerability.
CVE-2026-70611 (CVSS 7.5 — High Severity): Electron's DevTools embedder handler executes arbitrary files via shell open, allowing an attacker with capability to execute malicious code.
CVE-2026-70612: A sandboxed iframe can launch external protocol handlers in electron, potentially leading to a security vulnerability. These vulnerabilities collectively present a significant risk of exploitation by attackers. Administrators should review their exposure and apply updates to mitigate these risks. These vulnerabilities collectively present a significant risk of exploitation by attackers.
These vulnerabilities collectively present a significant risk of exploitation by attackers.
We recommend you to refer this link: https://github.com/electron/electron/releases/tag/v43.3.0
The following reports contain further technical details:
[/emaillocker]