CVE-2026-70604 | Electron up to 39.8.9/40.9.2/41.3.9 Custom Scheme cross-domain policy

SecurityVulns

A vulnerability described as problematic has been identified in Electron up to 39.8.9/40.9.2/41.3.9. The impacted element is an unknown function of the component Custom Scheme. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains.

This vulnerability is tracked as CVE-2026-70604. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More