CVE-2026-70604: CVE-2026-70604: Cross-Origin Resource Sharing (CORS) Bypass in Electron Custom Schemes
CVE-2026-70604: Cross-Origin Resource Sharing (CORS) Bypass in Electron Custom Schemes Vulnerability ID: CVE-2026-70604 CVSS Score: 7.4 Published: 2026-08-05 Electron custom schemes registered with supportFetchAPI:
CVE-2026-70604: Cross-Origin Resource Sharing (CORS) Bypass in Electron Custom Schemes
Vulnerability ID: CVE-2026-70604
CVSS Score: 7.4
Published: 2026-08-05
Electron custom schemes registered with supportFetchAPI: true but without corsEnabled: true failed to apply CORS enforcement in versions prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0. This mapping discrepancy allowed malicious remote pages to issue cross-origin requests, read sensitive local response data, and bypass Same-Origin Policy (SOP) mechanisms.
TL;DR
Electron custom protocols lacked CORS checks when supportFetchAPI was enabled without explicit corsEnabled configurations. This permitted remote pages to read sensitive local assets cross-origin.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-942: Permissive Cross-domain Policy with Untrusted Domains
- Attack Vector: Network (AV:N)
- CVSS v3.1: 7.4 (High Severity)
- Exploit Status: PoC (Proof-of-Concept) Available
- KEV Status: Not Listed
- Impact: Confidentiality Bypass / Same-Origin Policy (SOP) Break
Affected Systems
- Electron Framework
-
Electron: < 39.8.10 (Fixed in:
39.8.10) -
Electron: >= 40.0.0, < 40.9.3 (Fixed in:
40.9.3) -
Electron: >= 41.0.0, < 41.4.0 (Fixed in:
41.4.0) -
Electron: >= 42.0.0, < 42.0.0 (Fixed in:
42.0.0)
Mitigation Strategies
- Upgrade Electron to patched releases
- Explicitly set corsEnabled: true on custom protocols
- Disable supportFetchAPI if network requests to the protocol are unnecessary
- Implement robust Content Security Policies (CSP) to restrict data exfiltration
Remediation Steps:
- Identify all occurrences of protocol.registerSchemesAsPrivileged in the application's Main Process
- Verify if supportFetchAPI is set to true
- Ensure corsEnabled is explicitly declared as true for those protocols
- Update Electron dependency in package.json to at least 39.8.10, 40.9.3, 41.4.0, or 42.0.0
- Rebuild and redeploy the application
References
Read the full report for CVE-2026-70604 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.