Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin (CVE-2026-70599)
A vulnerability in Electron prior to versions 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1 causes the permission check handler to receive the main frame origin instead of the requesting iframe origin for serial-port and media device permissions. This can lead to cross-origin iframes gaining device access intended only for the top-level origin if the app uses origin-based logic with setPermissionCheckHandler. The issue affects apps that embed cross-origin iframes with delegated device permissions and use requestingOrigin for permission decisions. The vulnerability is fixed in the stated versions.
AI Analysis
Technical Summary
In Electron, for serial-port and media (camera/microphone) permission checks initiated from an iframe, the requestingOrigin parameter passed to session.setPermissionCheckHandler was incorrectly set to the top-level frame's origin rather than the origin of the requesting iframe. This flaw could allow origin-based permission handlers to mistakenly grant device access to cross-origin iframes that should not have it. The vulnerability only affects applications that use setPermissionCheckHandler with origin-based logic and embed cross-origin iframes with delegated device permissions. Applications that base permission decisions on details.securityOrigin or do not embed such iframes are not affected. The issue is addressed in Electron versions 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1.
Potential Impact
The vulnerability can lead to unauthorized device access (serial-port, camera, microphone) by cross-origin iframes if the application uses origin-based permission logic relying on requestingOrigin. This could result in a confidentiality breach of media or serial port devices. However, the impact is limited to applications that embed cross-origin iframes with delegated device permissions and use the affected permission check handler logic. There is no indication of integrity or availability impact.
Mitigation Recommendations
A fix is available in Electron versions 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1. Applications should upgrade to one of these versions or later. As a workaround, applications can check details.securityOrigin instead of requestingOrigin in their permission check handlers or avoid delegating device permissions to untrusted cross-origin iframes.
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin (CVE-2026-70599)
Description
A vulnerability in Electron prior to versions 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1 causes the permission check handler to receive the main frame origin instead of the requesting iframe origin for serial-port and media device permissions. This can lead to cross-origin iframes gaining device access intended only for the top-level origin if the app uses origin-based logic with setPermissionCheckHandler. The issue affects apps that embed cross-origin iframes with delegated device permissions and use requestingOrigin for permission decisions. The vulnerability is fixed in the stated versions.
CVSS v3.1
Score 5.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Electron, for serial-port and media (camera/microphone) permission checks initiated from an iframe, the requestingOrigin parameter passed to session.setPermissionCheckHandler was incorrectly set to the top-level frame's origin rather than the origin of the requesting iframe. This flaw could allow origin-based permission handlers to mistakenly grant device access to cross-origin iframes that should not have it. The vulnerability only affects applications that use setPermissionCheckHandler with origin-based logic and embed cross-origin iframes with delegated device permissions. Applications that base permission decisions on details.securityOrigin or do not embed such iframes are not affected. The issue is addressed in Electron versions 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1.
Potential Impact
The vulnerability can lead to unauthorized device access (serial-port, camera, microphone) by cross-origin iframes if the application uses origin-based permission logic relying on requestingOrigin. This could result in a confidentiality breach of media or serial port devices. However, the impact is limited to applications that embed cross-origin iframes with delegated device permissions and use the affected permission check handler logic. There is no indication of integrity or availability impact.
Mitigation Recommendations
A fix is available in Electron versions 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1. Applications should upgrade to one of these versions or later. As a workaround, applications can check details.securityOrigin instead of requestingOrigin in their permission check handlers or avoid delegating device permissions to untrusted cross-origin iframes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9pf5-hg6p-4pwp
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-70599"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a738520bf8831d5394ef958
Added to database: 08/05/2026, 18:46:56 UTC
Last enriched: 08/05/2026, 22:45:22 UTC
Last updated: 08/05/2026, 23:36:17 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.