FIVE high-severity vulnerabilities in the Electron framework were published by the Electron maintainers on 29 September 2026, with CVSS scores ranging from 7.4 to 8.3. All flaws allow untrusted content to escape a sandbox, an origin boundary, or a privilege limit set by the app. The fixes bundle in Electron 41.10.6, 42.10.0, 43.5.0, and 44.0.0-beta.6. Current guidance calls for upgrading to the latest releases and rebuilding affected apps.
The five CVEs are CVE-2026-102676 (8.3, not exploited), CVE-2026-102673 (8.2), CVE-2026-102674 (8.2), CVE-2026-102677 (7.8), and CVE-2026-102675 (7.4). The issues arise from different mechanisms: CVE-2026-102676 relates to Node[.]js integration in Web Workers, enabling a webview guest to gain higher privileges even when Node[.]js is disabled in the embedding page.
CVE-2026-102673 and CVE-2026-102674 involve popups escaping the sandbox via sandboxed iframes or top-level documents, allowing the popup to run with the app’s origin and access cookies and storage. CVE-2026-102677 concerns cache poisoning in the sandboxed preload code, while CVE-2026-102675 concerns readable cross-origin responses from custom schemes, completing a prior fix.
Affected versions span pre-41.10.6, pre-42.10.0, pre-43.5.0, and pre-44.0.0-beta.5, with CVE-2026-102677 restricted to 42.3.3 onward until 42.10.0, 43.5.0, and 44.0.0-beta.6. Exploitation in the wild is not confirmed for three of the CVEs.