top of page
perceptive_background_267k.jpg

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom s…

Published:

5 August 2026 at 00:00:00

Alert date:

5 August 2026 at 19:04:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

A vulnerability in the Electron framework allows remote origins to bypass CORS enforcement when a custom scheme is registered with supportFetchAPI: true but without corsEnabled: true. This means a page loaded from a remote origin can use fetch() or XMLHttpRequest to read the full response body from that custom scheme cross-origin, bypassing expected access restrictions. Applications that serve sensitive data via such custom schemes and load remote or untrusted content in a renderer process are at risk. The vulnerability affects Electron versions prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0. Fixes have been released in those respective versions. Developers using Electron with custom schemes and remote content should update immediately to mitigate potential data exposure.

Technical details

Mitigation steps:

Affected products:

Electron

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page