Feed/CVE-2026-70602
CVE-2026-70602MEDIUMCVSS 6.6

Electron: Extension tab APIs operate across session boundaries

Published Aug 5, 2026·Updated Aug 5, 2026

NVD Description

### Impact Extension tab and scripting APIs were not scoped to the extension's own `session`. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session. Apps are only affected if they load Chrome extensions via `session.loadExtension` and rely on separate sessions to isolate that extension from other content. Apps that do not load extensions, or that use a single session, are not affected. ### Workarounds Only load extensions from sources you trust; do not rely on session separation alone to contain an extension. ### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8` ### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)

Affected Packages (1)

electronNPM
Fixed in 39.8.8

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free