Electron: Context isolation bypass via Function.prototype.bind hijack (CVE-2026-70601)
Electron versions prior to 39.8.9 are vulnerable to a context isolation bypass via hijacking Function.prototype.bind. This affects apps that expose Promise-returning functions to web content through contextBridge, potentially allowing untrusted web content to access the isolated preload environment and escalate privileges to Node.js access in certain configurations. The vulnerability is fixed in Electron versions 39.8.9 and later.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-70601) in Electron allows a context isolation bypass when apps expose Promise-returning functions via contextBridge, the common pattern for ipcRenderer.invoke. Untrusted web content loaded in affected windows can gain access to the isolated preload world and all capabilities of the preload script. In renderers without sandboxing or with nodeIntegration enabled, this can escalate to Node.js access. The issue is fixed in Electron versions 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5.
Potential Impact
Untrusted web content in affected Electron apps can bypass context isolation protections, gaining access to the preload script environment and potentially escalating to Node.js access in certain configurations. This compromises the security boundary between web content and privileged Electron APIs, risking confidentiality and integrity of the host environment.
Mitigation Recommendations
There are no application-level workarounds. Users must update Electron to one of the patched versions: 39.8.9 or later. This is the only effective mitigation to prevent exploitation of this vulnerability.
Electron: Context isolation bypass via Function.prototype.bind hijack (CVE-2026-70601)
Description
Electron versions prior to 39.8.9 are vulnerable to a context isolation bypass via hijacking Function.prototype.bind. This affects apps that expose Promise-returning functions to web content through contextBridge, potentially allowing untrusted web content to access the isolated preload environment and escalate privileges to Node.js access in certain configurations. The vulnerability is fixed in Electron versions 39.8.9 and later.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-70601) in Electron allows a context isolation bypass when apps expose Promise-returning functions via contextBridge, the common pattern for ipcRenderer.invoke. Untrusted web content loaded in affected windows can gain access to the isolated preload world and all capabilities of the preload script. In renderers without sandboxing or with nodeIntegration enabled, this can escalate to Node.js access. The issue is fixed in Electron versions 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5.
Potential Impact
Untrusted web content in affected Electron apps can bypass context isolation protections, gaining access to the preload script environment and potentially escalating to Node.js access in certain configurations. This compromises the security boundary between web content and privileged Electron APIs, risking confidentiality and integrity of the host environment.
Mitigation Recommendations
There are no application-level workarounds. Users must update Electron to one of the patched versions: 39.8.9 or later. This is the only effective mitigation to prevent exploitation of this vulnerability.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-h7rp-cf8h-j98x
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-70601"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a73851fbf8831d5394ef89f
Added to database: 08/05/2026, 18:46:55 UTC
Last enriched: 08/05/2026, 19:11:51 UTC
Last updated: 08/05/2026, 19:11:51 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.