Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses on macOS to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enable fuse-based hardening restricting ELECTRONRUNASNODE and NODEOPTIONS to same-signed parents rely on this check, and a local attacker could bypass it and run code inside the signed app, inheriting its TCC permissions and keychain access. This issue is fixed in 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-367"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70597.json"
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "39.8.8"
},
{
"introduced": "40.0.0-alpha.1"
},
{
"fixed": "40.9.0"
},
{
"introduced": "41.0.0-alpha.1"
},
{
"fixed": "41.2.1"
},
{
"introduced": "42.0.0-alpha.1"
},
{
"fixed": "42.0.0-beta.3"
}
]
}"2026-08-07T22:16:26Z"
[
{
"target": {
"function": "WebContents::SetHtmlApiFullscreen",
"file": "shell/browser/api/electron_api_web_contents.cc"
},
"digest": {
"length": 490.0,
"function_hash": "272553221120290705100734388975204268805"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-70597-12b8aaae",
"source": "https://github.com/electron/electron/commit/8ee008ad48671e179d1b8258879871709babfff3"
},
{
"target": {
"file": "shell/common/mac/codesign_util.h"
},
"digest": {
"line_hashes": [
"155450920843387282329726254830061609506",
"139045894124710001186307451292535211346",
"73375244850893068628297843563777169775"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-70597-1bcdbdd2",
"source": "https://github.com/electron/electron/commit/0a6291a97d210db3733689e70a51f5711e38ed35"
},
{
"target": {
"file": "shell/browser/api/electron_api_web_contents.cc"
},
"digest": {
"line_hashes": [
"15682146902651291502359085377717075897",
"276527650456380695295071685428336688423",
"74027944338977948308663562070351154643",
"239644526509655375329227422095204640925"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-70597-60dfa0b4",
"source": "https://github.com/electron/electron/commit/8ee008ad48671e179d1b8258879871709babfff3"
},
{
"target": {
"function": "ProcessSignatureIsSameWithCurrentApp",
"file": "shell/common/mac/codesign_util.cc"
},
"digest": {
"length": 1378.0,
"function_hash": "314244285240983520216112363807807969086"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-70597-6d26b90a",
"source": "https://github.com/electron/electron/commit/0a6291a97d210db3733689e70a51f5711e38ed35"
},
{
"target": {
"file": "shell/app/node_main.cc"
},
"digest": {
"line_hashes": [
"24133243289240709261271448346904671826",
"58931597076854469931715209367760736665",
"153050882557885348092561396645399514902",
"25888038358916888464832430629966713284"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-70597-a45091d0",
"source": "https://github.com/electron/electron/commit/0a6291a97d210db3733689e70a51f5711e38ed35"
},
{
"target": {
"function": "NodeMain",
"file": "shell/app/node_main.cc"
},
"digest": {
"length": 4906.0,
"function_hash": "36035191146362469429278490665659231233"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2026-70597-cfd27a38",
"source": "https://github.com/electron/electron/commit/0a6291a97d210db3733689e70a51f5711e38ed35"
},
{
"target": {
"file": "shell/common/mac/codesign_util.cc"
},
"digest": {
"line_hashes": [
"287282249238570802168408299030077039178",
"65969256032293468206438238462085504420",
"328185831197212414241348286397466550053",
"6553313470447271797707655150668146631",
"99708648513123553471051972415049332443",
"180149766778540397685521243016542592808",
"242460259217449601815823507522450654043",
"46123759361872848230015691273634438699",
"198577698622930854968999101901669248104",
"50112581312842712925693280416188879561",
"283740900084610017018134010409056404339",
"219783027437042660376484551059836237848",
"238941451258296510196711402132560662086",
"30075276260452780917463299257210530378",
"36589711726425366822126512801917247714",
"116334897332000594367933781022818419429",
"279070967162877851202614009800636289377",
"338411988154508934823152087754737250091",
"108496213804459254958647457716934110746",
"11566217210321977732085529015781003266",
"84400744858144457956906788394374492226",
"22595822294447841795629547008957379314",
"46502182063266806494536577580625541009",
"10291377818356707140157124414690163888"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2026-70597-d1ccff6c",
"source": "https://github.com/electron/electron/commit/0a6291a97d210db3733689e70a51f5711e38ed35"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70597.json"