CVE-2026-70602: Medium severity npm/electron vulnerability
Impact Extension tab and scripting APIs were not scoped to the extension's own session. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session.
Apps are only affected if they load Chrome extensions via session.loadExtension and rely on separate sessions to isolate that extension from other content. Apps that do not load extensions, or that use a single session, are not affected.
Workarounds Only load extensions from sources you trust; do not rely on session separation alone to contain an extension.
Fixed Versions 42.0.0-beta.3 41.2.1 40.9.0 39.8.8
For more information If you have any questions or comments about this advisory, email Electron at security@electronjs.org
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 42.0.0-beta.3 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 41.2.1 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 40.9.0 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 39.8.8 - Upgrade
Upgrade
electronto a version that resolves this vulnerability.Fixed in 39.8.8 - Upgrade
Upgrade
electronto a version that resolves this vulnerability.Fixed in 40.9.0 - Upgrade
Upgrade
electronto a version that resolves this vulnerability.Fixed in 41.2.1 - Upgrade
Upgrade
electronto a version that resolves this vulnerability.Fixed in 42.0.0-beta.3 - Compensating control
Only load Chrome extensions from sources you trust; do not rely on session separation alone to contain an extension.