Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-70604: CVE-2026-70604: Cross-Origin Resource Sharing (CORS) Bypass in Electron Custom Schemes

CVE-2026-70604: Cross-Origin Resource Sharing (CORS) Bypass in Electron Custom Schemes Vulnerability ID: CVE-2026-70604 CVSS Score: 7.4 Published: 2026-08-05 Electron custom schemes registered with supportFetchAPI:

CVE-2026-70604: Cross-Origin Resource Sharing (CORS) Bypass in Electron Custom Schemes

Vulnerability ID: CVE-2026-70604
CVSS Score: 7.4
Published: 2026-08-05

Electron custom schemes registered with supportFetchAPI: true but without corsEnabled: true failed to apply CORS enforcement in versions prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0. This mapping discrepancy allowed malicious remote pages to issue cross-origin requests, read sensitive local response data, and bypass Same-Origin Policy (SOP) mechanisms.

TL;DR

Electron custom protocols lacked CORS checks when supportFetchAPI was enabled without explicit corsEnabled configurations. This permitted remote pages to read sensitive local assets cross-origin.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-942: Permissive Cross-domain Policy with Untrusted Domains
  • Attack Vector: Network (AV:N)
  • CVSS v3.1: 7.4 (High Severity)
  • Exploit Status: PoC (Proof-of-Concept) Available
  • KEV Status: Not Listed
  • Impact: Confidentiality Bypass / Same-Origin Policy (SOP) Break

Affected Systems

  • Electron Framework
  • Electron: < 39.8.10 (Fixed in: 39.8.10)
  • Electron: >= 40.0.0, < 40.9.3 (Fixed in: 40.9.3)
  • Electron: >= 41.0.0, < 41.4.0 (Fixed in: 41.4.0)
  • Electron: >= 42.0.0, < 42.0.0 (Fixed in: 42.0.0)

Mitigation Strategies

  • Upgrade Electron to patched releases
  • Explicitly set corsEnabled: true on custom protocols
  • Disable supportFetchAPI if network requests to the protocol are unnecessary
  • Implement robust Content Security Policies (CSP) to restrict data exfiltration

Remediation Steps:

  1. Identify all occurrences of protocol.registerSchemesAsPrivileged in the application's Main Process
  2. Verify if supportFetchAPI is set to true
  3. Ensure corsEnabled is explicitly declared as true for those protocols
  4. Update Electron dependency in package.json to at least 39.8.10, 40.9.3, 41.4.0, or 42.0.0
  5. Rebuild and redeploy the application

References

Read the full report for CVE-2026-70604 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.