Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer's code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6.
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
Problem type
Affected products
electron
>= 42.3.3, < 42.10.0 - AFFECTED
>= 43.0.0-beta.1, < 43.5.0 - AFFECTED
>= 44.0.0-alpha.1, < 44.0.0-beta.6 - AFFECTED
References
https://github.com/electron/electron/security/advisories/GHSA-qmv3-fv6v-rmhq
https://github.com/electron/electron/pull/52480
https://github.com/electron/electron/commit/000453e399bd1dee5e86376cdd9ece5fc071e601
https://github.com/electron/electron/commit/25ba8be57c65a83d8c14ebb8aa37693df17a04f3
https://github.com/electron/electron/commit/c38d6fd68756f04647ea857bdb6a2abec332e217
https://github.com/electron/electron/releases/tag/v42.10.0
https://github.com/electron/electron/releases/tag/v43.5.0
https://github.com/electron/electron/releases/tag/v44.0.0-beta.6
GitHub Security Advisories
GHSA-qmv3-fv6v-rmhq
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
https://github.com/advisories/GHSA-qmv3-fv6v-rmhqImpact
The cache Electron keeps for sandboxed preload scripts did not verify that a cached entry matched the preload it was served for. A compromised renderer could use this to run its own code in the preload context on a later load.
Apps are only affected if they load untrusted content. Apps that do not load untrusted content are not affected.
Workarounds
There are no app side workarounds, you must update to a patched version of Electron.
Fixed Versions
44.0.0-beta.643.5.042.10.0
For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org
https://github.com/electron/electron/security/advisories/GHSA-qmv3-fv6v-rmhq
https://github.com/electron/electron/pull/52480
https://github.com/electron/electron/commit/000453e399bd1dee5e86376cdd9ece5fc071e601
https://github.com/electron/electron/commit/06a12a87a23f40abbf580fc7a552bc1189812c45
https://github.com/electron/electron/commit/25ba8be57c65a83d8c14ebb8aa37693df17a04f3
https://github.com/electron/electron/commit/c38d6fd68756f04647ea857bdb6a2abec332e217
https://github.com/electron/electron/releases/tag/v42.10.0
https://github.com/electron/electron/releases/tag/v43.5.0
https://github.com/electron/electron/releases/tag/v44.0.0-beta.6
https://github.com/advisories/GHSA-qmv3-fv6v-rmhq
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-102677Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-102677",
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"dateUpdated": "2026-09-29T17:43:26.960Z",
"dateReserved": "2026-09-29T16:10:04.075Z",
"datePublished": "2026-09-29T17:43:26.960Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M",
"dateUpdated": "2026-09-29T17:43:26.960Z"
},
"title": "Electron: Sandboxed preload code cache can be poisoned by a compromised renderer",
"descriptions": [
{
"lang": "en",
"value": "Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer's code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6."
}
],
"affected": [
{
"vendor": "electron",
"product": "electron",
"versions": [
{
"version": ">= 42.3.3, < 42.10.0",
"status": "affected"
},
{
"version": ">= 43.0.0-beta.1, < 43.5.0",
"status": "affected"
},
{
"version": ">= 44.0.0-alpha.1, < 44.0.0-beta.6",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-20: Improper Input Validation",
"cweId": "CWE-20",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "CWE-345: Insufficient Verification of Data Authenticity",
"cweId": "CWE-345",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://github.com/electron/electron/security/advisories/GHSA-qmv3-fv6v-rmhq",
"name": "https://github.com/electron/electron/security/advisories/GHSA-qmv3-fv6v-rmhq",
"tags": [
"x_refsource_CONFIRM"
]
},
{
"url": "https://github.com/electron/electron/pull/52480",
"name": "https://github.com/electron/electron/pull/52480",
"tags": [
"x_refsource_MISC"
]
},
{
"url": "https://github.com/electron/electron/commit/000453e399bd1dee5e86376cdd9ece5fc071e601",
"name": "https://github.com/electron/electron/commit/000453e399bd1dee5e86376cdd9ece5fc071e601",
"tags": [
"x_refsource_MISC"
]
},
{
"url": "https://github.com/electron/electron/commit/25ba8be57c65a83d8c14ebb8aa37693df17a04f3",
"name": "https://github.com/electron/electron/commit/25ba8be57c65a83d8c14ebb8aa37693df17a04f3",
"tags": [
"x_refsource_MISC"
]
},
{
"url": "https://github.com/electron/electron/commit/c38d6fd68756f04647ea857bdb6a2abec332e217",
"name": "https://github.com/electron/electron/commit/c38d6fd68756f04647ea857bdb6a2abec332e217",
"tags": [
"x_refsource_MISC"
]
},
{
"url": "https://github.com/electron/electron/releases/tag/v42.10.0",
"name": "https://github.com/electron/electron/releases/tag/v42.10.0",
"tags": [
"x_refsource_MISC"
]
},
{
"url": "https://github.com/electron/electron/releases/tag/v43.5.0",
"name": "https://github.com/electron/electron/releases/tag/v43.5.0",
"tags": [
"x_refsource_MISC"
]
},
{
"url": "https://github.com/electron/electron/releases/tag/v44.0.0-beta.6",
"name": "https://github.com/electron/electron/releases/tag/v44.0.0-beta.6",
"tags": [
"x_refsource_MISC"
]
}
],
"metrics": [
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH"
}
}
]
}
}
}