What is CVE-2026-70602?
CVE-2026-70602 is a vulnerability in the Electron framework. Malicious extensions can access un-scoped tab and scripting APIs to interfere with other sessions. Applications using versions prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3 should be updated immediately.
Azərbaycanca: CVE-2026-70602 Electron framework-lərində zəiflikdir. Zərərli genişləndirmələr, eyni session-da olmayan API-lərə giriş əldə edərək digər session-lara müdaxilə edə bilər. Versiyaları 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3-dən aşağı olan tətbiqlər üçün yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which framework is affected by CVE-2026-70602?
The CVE-2026-70602 vulnerability affects the Electron framework.
Which Electron versions are vulnerable to CVE-2026-70602?
Applications using versions prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3 are vulnerable and should be updated.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.