TL;DR
Electron maintainers published five Electron vulnerabilities on September 29, 2026, all rated High, with CVSS scores from 7.4 to 8.3. Each flaw lets untrusted content escape a sandbox, an origin boundary, or a privilege limit set by the app. Fixed releases include Electron 41.10.6, 42.10.0, 43.5.0, and 44.0.0-beta.6.
- Total: 5 CVEs
- Severity: 5 High
- Actively exploited: None confirmed
- Highest severity: 8.3 (High · CVSSv3) — CVE-2026-102676
- Action: Apply the latest security updates now
See a CVE's exploit risk spike before it becomes a headline.
Get EPSS spike alertsNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-102676 | 8.3 | CWE-269 | Not exploited |
| CVE-2026-102673 | 8.2 | CWE-346 | Not exploited |
| CVE-2026-102674 | 8.2 | CWE-266 | Not exploited |
| CVE-2026-102677 | 7.8 | CWE-20 | Not exploited |
| CVE-2026-102675 | 7.4 | CWE-346 | Not exploited |
Why These Electron Vulnerabilities Matter
Electron powers desktop apps built with JavaScript, HTML, and CSS. Many popular chat, coding, and productivity tools ship on it. Because each app bundles its own copy of Electron, users stay exposed until every vendor ships an update.
The risk depends on how an app is built. Every flaw requires the app to load untrusted content, such as web pages, embedded frames, or a webview guest.
How the Attacks Work
Node.js in Web Workers (CVE-2026-102676, CVSS 8.3)
A webview guest could turn on Node.js integration for its Web Workers. This worked even when the embedding page had Node.js disabled. As a result, untrusted guest content could gain more privilege than the app granted.
Popups That Escape the Sandbox (CVE-2026-102673 and CVE-2026-102674, CVSS 8.2)
Two bugs let popups drop HTML sandbox restrictions. In the first, a sandboxed iframe opened a popup through a link or middle-click. In the second, a sandboxed top-level document opened a new window. Either way, the popup could run with the app’s full origin, exposing its cookies and storage.
Preload Cache Poisoning and Custom Schemes
CVE-2026-102677 (CVSS 7.8) affects the sandboxed preload code cache. Electron did not check that a cached entry matched its preload script. A compromised renderer could therefore get its own code run in the more privileged preload context. Meanwhile, CVE-2026-102675 (CVSS 7.4) left some custom scheme responses readable across origins. It completes an earlier fix for CVE-2026-70604.
Affected Versions and Exploitation Status
Most flaws affect versions before 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5. CVE-2026-102677 only affects 42.3.3 and later, until 42.10.0, 43.5.0, and 44.0.0-beta.6. CISA’s assessment lists “none” for exploitation on three of the CVEs. No exploitation in the wild or public proof-of-concept has been confirmed.
Patch and Mitigation Steps
Developers should upgrade to Electron 41.10.6, 42.10.0, 43.5.0, or 44.0.0-beta.6, then ship new app builds. Details for each issue appear in the Electron security advisories on GitHub. Until you update, deny unneeded popups with setWindowOpenHandler, keep embedders sandboxed, and avoid the webview tag where possible. These steps reduce exposure to the Electron vulnerabilities, but only a new build fully fixes them.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!