Sceawere
Vulnerability Detail
CVE-2026-102677UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Electron Preload Code Cache Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 7h ago
- Vendor
- electron
- Product
- electron
- Attack Type
- CWE-20: Improper Input Validation
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron's sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer's code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-09-29T18:17:09.573Z",
"pubdate": "2026-09-29T18:17:09.573Z",
"executiveSummary": "This vulnerability involves an improper validation mechanism in Electron's sandboxed preload code cache, classified as a security control bypass.\nThe flaw allows a compromised renderer process to inject attacker-controlled data into the cache, which is subsequently executed within the context of the more privileged preload script.\nAffected products include Electron versions 42.3.3 through 42.10.0, 43.5.0, and 44.0.0-beta.6.\nThe impact of this vulnerability is significant, as it facilitates privilege escalation from a sandboxed renderer to the privileged preload context, potentially leading to full application compromise or arbitrary code execution on the host system.\nExploitation requires the application to load untrusted or malicious content, which serves as the entry point for an attacker to compromise the renderer process and manipulate the code cache entries.\nThis vulnerability represents a critical risk for Electron-based applications that handle external or user-provided web content, necessitating an immediate upgrade to the patched versions.",
"technicalDetails": "The root cause of the vulnerability lies in the failure of the Electron framework to cryptographically verify or structurally validate the integrity of cached preload script data against the actual source file it is intended to represent.\nIn Electron's architecture, preload scripts run with elevated privileges compared to the renderer process. To optimize performance, Electron caches compiled code for these scripts. The vulnerability exists because the caching mechanism does not perform a robust consistency check to ensure the cached entry matches the preload script currently being loaded.\nThe attack flow begins when an attacker gains control over the renderer process, typically by exploiting a cross-site scripting (XSS) vulnerability or by injecting malicious content into a web view that processes untrusted data.\nOnce the renderer is compromised, the attacker can manipulate the local filesystem or the cache storage mechanism utilized by Electron. By overwriting or substituting a valid cached preload entry with malicious, attacker-controlled byte code, the attacker can force the system to load this malicious payload the next time the preload script is initialized.\nBecause the system trusts the cached entry, it bypasses standard security checks that would otherwise prevent unauthorized code execution. The malicious payload is subsequently executed within the higher-privilege preload context, effectively breaking the security boundary between the renderer and the privileged process.\nThis privilege escalation enables the execution of arbitrary JavaScript within the privileged environment, granting the attacker access to Node.js APIs and internal Electron functionality that are otherwise restricted within the renderer sandbox.\nThe flaw affects versions 42.3.3 through 42.10.0, 43.5.0, and 44.0.0-beta.6. There are no authentication requirements for exploitation beyond the initial compromise of the renderer, and the attack operates entirely within the local context of the application's runtime environment.\nPost-exploitation, an attacker can achieve full control over the application's process, perform unauthorized file system operations, and potentially pivot to the underlying operating system, depending on the application's configured permissions and the platform's security controls."
}