Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-70610— Electron: contextBridge object copy honors prototype setters

CVSS 5.4 · Medium

Affected Version Matrix 4

VendorProductVersion RangeStatus
electronelectron< 39.8.9affected
>= 40.0.0-alpha.1, < 40.9.2affected
>= 41.0.0-alpha.1, < 41.2.2affected
>= 42.0.0-alpha.1, < 42.0.0-beta.4affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-70610

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Electron: contextBridge object copy honors prototype setters
Source: CVE Program / CVE List V5
Vulnerability Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry an attacker-influenced prototype, enabling prototype-pollution-style attacks against preload code despite context isolation being enabled. Apps are only affected if their preload code accepts object arguments from untrusted content and reads properties from them without own-property checks, while apps that only accept primitive arguments or validate object arguments are not affected. This issue is fixed in 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1321
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
electronelectron < 39.8.9 -

II. Public POCs for CVE-2026-70610

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-70610

登录查看更多情报信息。

Patches & Fixes for CVE-2026-70610 (8)

Vendor Advisories for CVE-2026-70610 (1)

Vendor Pages for CVE-2026-70610 (4)

Same Patch Batch · electron · 2026-08-05 · 16 CVEs total

CVE-2026-706017.5 HIGHElectron: Context isolation bypass via Function.prototype.bind hijack
CVE-2026-706047.4 HIGHElectron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin rea
CVE-2026-706087.2 HIGHElectron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigat
CVE-2026-706116.9 MEDIUMElectron: DevTools embedder handler executes arbitrary files via shell open
CVE-2026-706026.6 MEDIUMElectron: Extension tab APIs operate across session boundaries
CVE-2026-705976.3 MEDIUMElectron: Parent process code-sign check is spoofable
CVE-2026-706036.0 MEDIUMElectron: shell.openPath path validation bypass via embedded null byte
CVE-2026-706055.9 MEDIUMElectron: HTTP redirect followed into local file loader
CVE-2026-706065.9 MEDIUMElectron: ProtocolResponse.url reuses the default session cache instead of the registering
CVE-2026-705995.9 MEDIUMElectron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe
CVE-2026-706095.7 MEDIUMElectron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
CVE-2026-706125.4 MEDIUMElectron: Sandboxed iframes can launch external protocol handlers
CVE-2026-706075.3 MEDIUMElectron: window.open features string controls some window options considered privileged
CVE-2026-705983.9 LOWElectron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
CVE-2026-706003.1 LOWElectron: Cross-origin iframe can position native autofill popup

IV. Related Vulnerabilities

V. Comments for CVE-2026-70610

No comments yet


Leave a comment