CVE-2026-70600 Details
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup could be positioned by a cross-origin iframe outside that iframe's bounds, over the embedding page's UI, enabling clickjacking or spoofing of trusted UI. Apps are only affected if they embed untrusted content in iframes within windows that also display trusted UI. Apps that do not embed untrusted third-party content are not affected. This issue is fixed in versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.
A vulnerability in Electron's native autofill feature allows cross-origin iframes to manipulate the autofill popup's position, potentially overlaying it on trusted user interface elements of the embedding page. This issue could lead to clickjacking or spoofing of trusted UI. The vulnerability affects Electron applications that embed untrusted content in iframes within windows displaying trusted UI. It is present in Electron versions prior to 39.8.8, as well as versions 40.0.0-alpha.1 through 40.9.0, 41.0.0-alpha.1 through 41.2.1, and 42.0.0-alpha.1 through 42.0.0-beta.3.
Users can upgrade to Electron versions 39.8.8, 40.9.0, 41.2.1, or 42.0.0-beta.3 to address this vulnerability. Alternatively, untrusted content should not be embedded in iframes within windows that display trusted UI.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/electron/electron/security/advisories/GHSA-x8rc-wpg4-grpf | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1021 | Improper Restriction of Rendered UI Layers or Frames | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |