2026-09-29 17:43CVE-2026-102677GitHub_M
PUBLISHED5.2CWE-20CWE-345

Electron: Sandboxed preload code cache can be poisoned by a compromised renderer

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer's code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6.

Problem type

Affected products

electron

electron

>= 42.3.3, < 42.10.0 - AFFECTED

>= 43.0.0-beta.1, < 43.5.0 - AFFECTED

>= 44.0.0-alpha.1, < 44.0.0-beta.6 - AFFECTED

References

GitHub Security Advisories

GHSA-qmv3-fv6v-rmhq

Electron: Sandboxed preload code cache can be poisoned by a compromised renderer

https://github.com/advisories/GHSA-qmv3-fv6v-rmhq

Impact

The cache Electron keeps for sandboxed preload scripts did not verify that a cached entry matched the preload it was served for. A compromised renderer could use this to run its own code in the preload context on a later load.

Apps are only affected if they load untrusted content. Apps that do not load untrusted content are not affected.

Workarounds

There are no app side workarounds, you must update to a patched version of Electron.

Fixed Versions

  • 44.0.0-beta.6
  • 43.5.0
  • 42.10.0

For more information

If you have any questions or comments about this advisory, email us at security@electronjs.org

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-102677
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-102677",
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "dateUpdated": "2026-09-29T17:43:26.960Z",
    "dateReserved": "2026-09-29T16:10:04.075Z",
    "datePublished": "2026-09-29T17:43:26.960Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M",
        "dateUpdated": "2026-09-29T17:43:26.960Z"
      },
      "title": "Electron: Sandboxed preload code cache can be poisoned by a compromised renderer",
      "descriptions": [
        {
          "lang": "en",
          "value": "Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer's code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6."
        }
      ],
      "affected": [
        {
          "vendor": "electron",
          "product": "electron",
          "versions": [
            {
              "version": ">= 42.3.3, < 42.10.0",
              "status": "affected"
            },
            {
              "version": ">= 43.0.0-beta.1, < 43.5.0",
              "status": "affected"
            },
            {
              "version": ">= 44.0.0-alpha.1, < 44.0.0-beta.6",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-20: Improper Input Validation",
              "cweId": "CWE-20",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-345: Insufficient Verification of Data Authenticity",
              "cweId": "CWE-345",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/electron/electron/security/advisories/GHSA-qmv3-fv6v-rmhq",
          "name": "https://github.com/electron/electron/security/advisories/GHSA-qmv3-fv6v-rmhq",
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/electron/electron/pull/52480",
          "name": "https://github.com/electron/electron/pull/52480",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/electron/electron/commit/000453e399bd1dee5e86376cdd9ece5fc071e601",
          "name": "https://github.com/electron/electron/commit/000453e399bd1dee5e86376cdd9ece5fc071e601",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/electron/electron/commit/25ba8be57c65a83d8c14ebb8aa37693df17a04f3",
          "name": "https://github.com/electron/electron/commit/25ba8be57c65a83d8c14ebb8aa37693df17a04f3",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/electron/electron/commit/c38d6fd68756f04647ea857bdb6a2abec332e217",
          "name": "https://github.com/electron/electron/commit/c38d6fd68756f04647ea857bdb6a2abec332e217",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/electron/electron/releases/tag/v42.10.0",
          "name": "https://github.com/electron/electron/releases/tag/v42.10.0",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/electron/electron/releases/tag/v43.5.0",
          "name": "https://github.com/electron/electron/releases/tag/v43.5.0",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/electron/electron/releases/tag/v44.0.0-beta.6",
          "name": "https://github.com/electron/electron/releases/tag/v44.0.0-beta.6",
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "CHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH"
          }
        }
      ]
    }
  }
}