Electron: Sandboxed preload code cache can be poisoned by a compromised renderer
Published Sep 29, 2026
7.8
HIGHCVSS 3.1
EPSS 0.09%
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer's code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6.
Affected products
-
- Version >= 42.3.3, < 42.10.0StatusaffectedConstraints-
- Version >= 43.0.0-beta.1, < 43.5.0StatusaffectedConstraints-
- Version >= 44.0.0-alpha.1, < 44.0.0-beta.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Build of Podman Desktop
rh-podman-desktop
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Build of Podman Desktop | rh-podman-desktop | Affected | n/a |
electron
npm
Introduced 42.3.3 Fixed 42.10.0electron
npm
Introduced 43.0.0-beta.1 Fixed 43.5.0electron
npm
Introduced 44.0.0-alpha.1 Fixed 44.0.0-beta.6
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | electron | 42.3.3 | 42.10.0 |
| npm | electron | 43.0.0-beta.1 | 43.5.0 |
| npm | electron | 44.0.0-alpha.1 | 44.0.0-beta.6 |
Remediation
Red Hat statement
A flaw was found in Electron's sandboxed preload code cache mechanism. When applications load untrusted content, a compromised renderer process can write unverified cache entries that are subsequently loaded during future script executions. This allows a local attacker to execute arbitrary code within the higher-privileged preload execution context, bypassing sandbox isolation boundaries.
Red Hat mitigation
Disable loading untrusted web content within Electron renderer processes or isolate untrusted origins into dedicated web views with disabled preload scripts.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (14)
- https://access.redhat.com/security/cve/CVE-2026-102677 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2543491 Issue Tracking
- https://github.com/advisories/GHSA-qmv3-fv6v-rmhq Advisory
- https://github.com/electron/electron/commit/000453e399bd1dee5e86376cdd9ece5fc071e601 x_refsource_MISC
- https://github.com/electron/electron/commit/06a12a87a23f40abbf580fc7a552bc1189812c45
- https://github.com/electron/electron/commit/25ba8be57c65a83d8c14ebb8aa37693df17a04f3 x_refsource_MISC
- https://github.com/electron/electron/commit/c38d6fd68756f04647ea857bdb6a2abec332e217 x_refsource_MISC
- https://github.com/electron/electron/pull/52480 x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v42.10.0 x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v43.5.0 x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v44.0.0-beta.6 x_refsource_MISC
- https://github.com/electron/electron/security/advisories/GHSA-qmv3-fv6v-rmhq x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-102677
- https://www.cve.org/CVERecord?id=CVE-2026-102677
Change history (0)
No recorded changes yet.