What is CVE-2026-70600?
CVE-2026-70600 is a vulnerability in the Electron framework where a cross-origin iframe could position the native autofill popup outside its bounds, overlaying the embedding page's UI. This may enable clickjacking attacks where users are tricked into clicking on overlayed UI elements. Affected users should upgrade to versions 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 or later.
Azərbaycanca: CVE-2026-70600 Electron çərçivəsində aşkar edilmiş boşluqdur ki, çarpaz mənşəli (cross-origin) iframe daxilində işləyən native autofill popup-un iframe sərhədlərindən kənara yerləşdirilməsinə imkan verir. Bu, istifadəçi aldadılaraq əsas səhifənin UI elementləri üzərindən kliklərin tutulmasına (clickjacking) səbəb ola bilər. Təsirə məruz qalan versiyaları istifadə edən tərtibatçılar dərhal 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 və ya daha yuxarı versiyalara yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
What security risk does CVE-2026-70600 pose in the Electron framework?
This vulnerability allows a cross-origin iframe to position the native autofill popup outside its bounds, overlaying the embedding page's UI. This can trick users into clicking on overlayed UI elements, potentially enabling clickjacking attacks.
Which Electron versions should be upgraded to in order to mitigate CVE-2026-70600?
Affected users should upgrade to versions 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.