AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70612

MEDIUM · CVSS 5.4 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability affects Electron applications that utilize sandboxed iframes, allowing malicious web content to bypass iframe restrictions and launch OS-registered external applications. This could lead to unauthorized access or execution of potentially harmful applications on the user's system. Developers of Electron-based applications, especially those rendering untrusted content, should prioritize updating to the patched versions to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-70612
Severity
MEDIUM
CVSS
5.4
EPSS
0.36%
Java

Original NVD Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered external application to be launched. The frame sandbox state was also not made available to the app permission handlers, affecting apps that render untrusted content in sandboxed iframes and grant the openExternal permission by default when no setPermissionRequestHandler is installed. This issue is fixed in 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.