Cross-Origin Vulnerability in Electron Framework for Desktop Applications
CVE-2026-102675
What is CVE-2026-102675?
A cross-origin vulnerability exists in the Electron framework prior to specified versions due to improper handling of protocol responses. When custom schemes are registered with supportFetchAPI enabled but corsEnabled disabled, responses can potentially remain readable across origins, creating risks for untrusted content loaded within the same session. This vulnerability emphasizes the importance of using appropriate configuration settings when registering protocols, especially in applications that handle sensitive data. Upgrading to the latest versions ensures applications are safeguarded against this issue.
Affected Version(s)
electron < 41.10.6 < 41.10.6
electron >= 42.0.0-alpha.1, < 42.9.2 < 42.0.0-alpha.1, 42.9.2
electron >= 43.0.0-alpha.1, < 43.4.1 < 43.0.0-alpha.1, 43.4.1
