Feed/CVE-2026-70600
CVE-2026-70600LOWCVSS 3.1

Electron: Cross-origin iframe can position native autofill popup

Published Aug 5, 2026·Updated Aug 5, 2026

NVD Description

### Impact The native autofill popup could be positioned by a cross-origin iframe outside that iframe's bounds, over the embedding page's UI, enabling clickjacking or spoofing of trusted UI. Apps are only affected if they embed untrusted content in iframes within windows that also display trusted UI. Apps that do not embed untrusted third-party content are not affected. ### Workarounds Do not embed untrusted content in iframes inside windows that display trusted UI. ### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8` ### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)

Affected Packages (1)

electronNPM
Fixed in 39.8.8

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free