


Perceptive Security
SOC/SIEM Consultancy

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps…
Published:
4 August 2026 at 22:00:00
Alert date:
5 August 2026 at 17:04:40
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A security vulnerability in the Electron framework allows untrusted web content to bypass context isolation via Promise-returning functions exposed through contextBridge. Affected versions include Electron prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5. Exploiting this flaw allows untrusted content to access the isolated preload world and all capabilities of the preload script. In renderers without a sandbox or with nodeIntegration enabled, this can escalate to full Node.js access, significantly broadening the attack surface. Apps using the common pattern of wrapping ipcRenderer.invoke via contextBridge in windows loading untrusted content are specifically at risk. The vulnerability has been patched in versions 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5. Developers are urged to update their Electron installations immediately to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
Electron
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-70601
https://github.com/electron/electron/security/advisories/GHSA-h7rp-cf8h-j98x
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
