CVE-2026-102677
🟡 Monitoruj
Błąd w Electron umożliwia złośliwemu rendererowi wykonanie kodu w kontekście preload.
CVSS
7.8
EPSS
0.1%
Exploit
none
Vendor
Opis źródłowy (NVD)
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer's code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2026-09-29 18:17:09 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 13:17:19 UTC |
Referencje
- https://github.com/electron/electron/commit/000453e399bd1dee5e86376cdd9ece5fc071e601 ([email protected])
- https://github.com/electron/electron/commit/25ba8be57c65a83d8c14ebb8aa37693df17a04f3 ([email protected])
- https://github.com/electron/electron/commit/c38d6fd68756f04647ea857bdb6a2abec332e217 ([email protected])
- https://github.com/electron/electron/pull/52480 ([email protected])
- https://github.com/electron/electron/releases/tag/v42.10.0 ([email protected])
- https://github.com/electron/electron/releases/tag/v43.5.0 ([email protected])
- https://github.com/electron/electron/releases/tag/v44.0.0-beta.6 ([email protected])
- https://github.com/electron/electron/security/advisories/GHSA-qmv3-fv6v-rmhq ([email protected])