{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/electron-39.x-40.x-41.x-42.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-70604"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Electron (39.x, 40.x, 41.x, 42.x)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Electron"],"content_html":"\u003cp\u003eElectron has disclosed a security vulnerability identified as CVE-2026-70604, affecting applications that utilize custom protocol schemes. The issue arises when a custom scheme is registered with \u003ccode\u003esupportFetchAPI: true\u003c/code\u003e but fails to enable \u003ccode\u003ecorsEnabled: true\u003c/code\u003e. Under these conditions, the Electron framework fails to enforce Cross-Origin Resource Sharing (CORS) policies.\u003c/p\u003e\n\u003cp\u003eThis architectural flaw allows a remote origin, if loaded within a renderer process, to perform \u003ccode\u003efetch()\u003c/code\u003e or \u003ccode\u003eXMLHttpRequest\u003c/code\u003e operations against the custom scheme. Consequently, the remote origin can read the full response body of these requests, leading to potential data exfiltration of sensitive information processed by the local application. The vulnerability impacts multiple versions across the 39.x, 40.x, 41.x, and 42.x branches. Defenders should note that applications are only affected if they load untrusted content within their renderer processes and fail to explicitly enable CORS for these schemes.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized cross-origin read access to sensitive data handled by the application's internal custom protocols. This can result in the exfiltration of user session tokens, local configuration files, or sensitive business data processed by the Electron-based application. The severity of the impact depends on the sensitivity of the data served by the custom protocol and the extent to which the application displays third-party or untrusted web content.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to patched versions: 39.8.10, 40.9.3, 41.4.0, or 42.0.0.\u003c/li\u003e\n\u003cli\u003eAudit application code for registrations of custom protocols using the \u003ccode\u003eprotocol\u003c/code\u003e module; ensure that \u003ccode\u003ecorsEnabled\u003c/code\u003e is set to \u003ccode\u003etrue\u003c/code\u003e for any scheme serving sensitive data.\u003c/li\u003e\n\u003cli\u003eImplement strict \u003ccode\u003eOrigin\u003c/code\u003e header validation within protocol handler functions to ensure that only authorized origins can access sensitive data.\u003c/li\u003e\n\u003cli\u003eDisable the loading of remote, untrusted content in renderer processes wherever possible to eliminate the attack vector.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T21:26:17Z","date_published":"2026-08-05T21:26:17Z","id":"https://feed.craftedsignal.io/briefs/2026-08-electron-cors-bypass/","summary":"A vulnerability in Electron (CVE-2026-70604) allows remote origins to bypass CORS protections when interacting with custom schemes, enabling unauthorized read access to sensitive data.","title":"Electron CORS Protection Bypass via Custom Schemes","url":"https://feed.craftedsignal.io/briefs/2026-08-electron-cors-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Electron (39.x, 40.x, 41.x, 42.x)","version":"https://jsonfeed.org/version/1.1"}