MEDIUM
Electron: Local race condition in Squirrel.Mac update installation on macOS
Published Sep 29, 2026
6.7
MEDIUMCVSS 3.1
Description
Electron: Local race condition in Squirrel.Mac update installation on macOS
Affected products
No data.
No data.
No data.
No Red Hat product state for this CVE.
electron
npm
Introduced 0 Fixed 39.8.10electron
npm
Introduced 40.0.0-alpha.1 Fixed 41.10.5electron
npm
Introduced 42.0.0-alpha.1 Fixed 42.0.0-beta.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | electron | 0 | 39.8.10 |
| npm | electron | 40.0.0-alpha.1 | 41.10.5 |
| npm | electron | 42.0.0-alpha.1 | 42.0.0-beta.2 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
6.7 MEDIUM GHSA
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction Required
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
Weaknesses (1)
References (10)
- https://github.com/advisories/GHSA-vv43-5jgx-7qv8 Advisory
- https://github.com/electron/electron/commit/01faabfc250801a980fc94d64608046c67fc1cd9
- https://github.com/electron/electron/commit/15e2928a5c5f01759107b414010e220d90d59cef
- https://github.com/electron/electron/commit/a0f9ff4cc0340545008424232d49caadd9c0c767
- https://github.com/electron/electron/commit/b8f25c4cedb2e0f5f475912b709aba19c57c26be
- https://github.com/electron/electron/pull/50745
- https://github.com/electron/electron/releases/tag/v39.8.10
- https://github.com/electron/electron/releases/tag/v41.10.5
- https://github.com/electron/electron/releases/tag/v42.0.0-beta.2
- https://github.com/electron/electron/security/advisories/GHSA-vv43-5jgx-7qv8
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status n/a
Assigner n/a
Published Sep 29, 2026
Updated n/a
Reserved n/a
Link CVE-2026-102672
CISA Vulnrichment
GHSA-VV43-5JGX-7QV8 Updated n/a