Cross-Origin Device Access Vulnerability in Electron Framework
CVE-2026-70599

5.9MEDIUM

Key Information:

Vendor

Electron

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-70599?

A security flaw in the Electron framework allows improper handling of origin checks for device access permissions, potentially permitting cross-origin iframes to access devices meant for the top-level origin. This vulnerability, present in versions prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, could expose sensitive device interactions, necessitating urgent updates for users to ensure robust application security.

Affected Version(s)

electron < 39.8.7 < 39.8.7

electron >= 40.0.0-alpha.1, < 40.9.0 < 40.0.0-alpha.1, 40.9.0

electron >= 41.0.0-alpha.1, < 41.2.0 < 41.0.0-alpha.1, 41.2.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.