


Perceptive Security
SOC/SIEM Consultancy

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom s…
Published:
4 August 2026 at 22:00:00
Alert date:
5 August 2026 at 17:04:40
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A vulnerability in the Electron framework allows remote origins to bypass CORS enforcement when a custom scheme is registered with supportFetchAPI: true but without corsEnabled: true. This means a page loaded from a remote origin can use fetch() or XMLHttpRequest to read the full response body from that custom scheme cross-origin, bypassing expected access restrictions. Applications that serve sensitive data via such custom schemes and load remote or untrusted content in a renderer process are at risk. The vulnerability affects Electron versions prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0. Fixes have been released in those respective versions. Developers using Electron with custom schemes and remote content should update immediately to mitigate potential data exposure.
Technical details
Mitigation steps:
Affected products:
Electron
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-70604
https://github.com/electron/electron/security/advisories/GHSA-v3j7-r9gq-3gjw
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
