Back

HIGH

Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled

Published Sep 29, 2026

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI enabled but corsEnabled disabled could remain script-readable across origins. This residual issue completes the remediation for CVE-2026-70604. Applications are affected only when they expose such a scheme and load untrusted content in the same session. Schemes intentionally registered with corsEnabled enabled remain cross-origin readable by design. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.

Affected products

Remediation

Red Hat statement

A flaw was found in Electron where responses served via protocol.registerFileProtocol or protocol.registerHttpProtocol for custom schemes registered with supportFetchAPI enabled but corsEnabled disabled remain script-readable across origins. If untrusted content is loaded within the same session, an attacker can exploit this behavior to bypass the same-origin policy and read sensitive application data, resulting in information disclosure.

Red Hat mitigation

Ensure custom schemes registered with supportFetchAPI explicitly enable corsEnabled, or avoid loading untrusted web content within sessions where custom protocol schemes with disabled CORS controls are registered.

Metrics

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 29, 2026
Updated Sep 29, 2026
Reserved Sep 29, 2026
CISA Vulnrichment
Updated Sep 29, 2026
NVD
Status Awaiting Analysis
Modified Sep 30, 2026
Red Hat
Severity Important
Public date Sep 29, 2026
GHSA-J84W-JFHQ-VHVJ