CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-70604

highCVSS 7.4covered by 2 sourcesfirst seen 2026-08-05
Impact A custom scheme registered with supportFetchAPI: true but without corsEnabled: true was not subject to CORS enforcement. A page loaded from a remote origin could therefore fetch() or XMLHttpRequest that scheme cross-origin and read the full response body, rather than the read being blocked. Apps that serve sensitive data from such a scheme and load remote or untrusted content in a renderer are affected. Apps that set corsEnabled: true, or that do not load untrusted content, are not affected. Workarounds Set corsEnabled: true on schemes that must enforce CORS, and validate the request Origin in your protocol handler before returning sensitive data. Fixed Versions - 42.0.0 - 41.4.0 - 40.9.3 - 39.8.10 For more information If you have any questions or comments about this advisory, email Electron at security@electronjs.org

⚡ Watch CVE-2026-70604

Get an email if CVE-2026-70604 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-70604

CVE.org record

Embed the live status

CVE-2026-70604 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-70604 status](https://www.csirts.com/badge/CVE-2026-70604)](https://www.csirts.com/cve/CVE-2026-70604)