Back

HIGH

Electron: Sandboxed preload code cache can be poisoned by a compromised renderer

Published Sep 29, 2026

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer's code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6.

Affected products

Remediation

Red Hat statement

A flaw was found in Electron's sandboxed preload code cache mechanism. When applications load untrusted content, a compromised renderer process can write unverified cache entries that are subsequently loaded during future script executions. This allows a local attacker to execute arbitrary code within the higher-privileged preload execution context, bypassing sandbox isolation boundaries.

Red Hat mitigation

Disable loading untrusted web content within Electron renderer processes or isolate untrusted origins into dedicated web views with disabled preload scripts.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 29, 2026
Updated Sep 29, 2026
Reserved Sep 29, 2026
NVD
Status Awaiting Analysis
Modified Sep 30, 2026
Red Hat
Severity Important
Public date Sep 29, 2026
GHSA-QMV3-FV6V-RMHQ