Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level frame origin to session.setPermissionCheckHandler instead of the requesting iframe origin. Origin-based handler logic could grant a cross-origin iframe device access intended only for the top-level origin. This issue is fixed in 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70599.json",
"cwe_ids": [
"CWE-346"
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "39.8.7"
},
{
"introduced": "40.0.0-alpha.1"
},
{
"fixed": "40.9.0"
},
{
"introduced": "41.0.0-alpha.1"
},
{
"fixed": "41.2.0"
},
{
"introduced": "42.0.0-alpha.1"
},
{
"fixed": "42.0.0-beta.1"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"2026-08-07T22:16:25Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70599.json"
[
{
"signature_type": "Function",
"target": {
"file": "shell/browser/web_contents_permission_helper.cc",
"function": "WebContentsPermissionHelper::CheckMediaAccessPermission"
},
"deprecated": false,
"digest": {
"length": 424.0,
"function_hash": "14638935377816536723056231755827218625"
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/0cbdf2f0375466d701aa393c92e0ec29eb89ea6c",
"id": "CVE-2026-70599-2089717b"
},
{
"signature_type": "Function",
"target": {
"file": "shell/browser/web_contents_permission_helper.cc",
"function": "WebContentsPermissionHelper::CheckPermission"
},
"deprecated": false,
"digest": {
"length": 415.0,
"function_hash": "51491720150667301252856673348526243552"
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/0cbdf2f0375466d701aa393c92e0ec29eb89ea6c",
"id": "CVE-2026-70599-24d9e74a"
},
{
"signature_type": "Line",
"target": {
"file": "shell/browser/serial/electron_serial_delegate.cc"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"181560885068120511271465018724902127438",
"118127262335597810325197895275564425523",
"10912655876559776613180912148594555956",
"322052165961764670241511209337899699899",
"173112705583545695261632442586889270661"
]
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/0cbdf2f0375466d701aa393c92e0ec29eb89ea6c",
"id": "CVE-2026-70599-7fd73678"
},
{
"signature_type": "Line",
"target": {
"file": "shell/browser/web_contents_permission_helper.h"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"269655604508682479632906856513772671928",
"141549379148472863917181489213345670753",
"182716820291680778954426341179992922884",
"109670589892792486283533594488369452203",
"117253726913024203327624067849295615556",
"79433908352023975796131166671519939053",
"163618578562136055652424772491721451900",
"206745233441488457919680494846765237967",
"54047954756742812118457205228696492864",
"264085488797745858112339743384579483636"
]
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/0cbdf2f0375466d701aa393c92e0ec29eb89ea6c",
"id": "CVE-2026-70599-96da8e81"
},
{
"signature_type": "Function",
"target": {
"file": "shell/browser/api/electron_api_web_contents.cc",
"function": "WebContents::CheckMediaAccessPermission"
},
"deprecated": false,
"digest": {
"length": 309.0,
"function_hash": "114782798748351219880551690314793610151"
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/0cbdf2f0375466d701aa393c92e0ec29eb89ea6c",
"id": "CVE-2026-70599-9b66ee97"
},
{
"signature_type": "Function",
"target": {
"file": "shell/browser/web_contents_permission_helper.cc",
"function": "WebContentsPermissionHelper::CheckSerialAccessPermission"
},
"deprecated": false,
"digest": {
"length": 253.0,
"function_hash": "186831020629867633579429287650941774929"
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/0cbdf2f0375466d701aa393c92e0ec29eb89ea6c",
"id": "CVE-2026-70599-9f5b032e"
},
{
"signature_type": "Function",
"target": {
"file": "shell/browser/serial/electron_serial_delegate.cc",
"function": "ElectronSerialDelegate::CanRequestPortPermission"
},
"deprecated": false,
"digest": {
"length": 305.0,
"function_hash": "283806427063958704427882877988519323105"
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/0cbdf2f0375466d701aa393c92e0ec29eb89ea6c",
"id": "CVE-2026-70599-d189b22a"
},
{
"signature_type": "Line",
"target": {
"file": "shell/browser/web_contents_permission_helper.cc"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"98569589963065280022175374611532746795",
"168790573428302094392459535773098567881",
"260965501140299108189946704791827462033",
"6397055152190510807986976913035935836",
"319153104038900295132542292303420643139",
"339087940117065424249916939131214524120",
"313715398902363648834053963820000194772",
"258361593649538140283568582668152628388",
"175737800340193260258315958561548803391",
"326149349561598186525688114265440576395",
"86951331118430262636138952231990818379",
"228497794972198619003906657034164486342",
"264471538076211830192705884875614971108",
"4096368838716404710283713914152912413",
"56602801851220056746429945196701361617",
"143920318627831586600355029058941849152",
"25954394589008093086526526548902207240",
"188210446418126682277563926483347080532",
"162304109869587719969479127745662910477",
"283782820553492321742289958524024021604",
"319764716758839982738800844277608155125",
"324331077020838294242178964171535937342",
"261612056150242696522692031825312914712",
"92319678898836175756018158275380224385",
"143042073497004371251759609297223069928",
"215670571776003240786408724517685077655"
]
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/0cbdf2f0375466d701aa393c92e0ec29eb89ea6c",
"id": "CVE-2026-70599-d749488c"
},
{
"signature_type": "Line",
"target": {
"file": "shell/browser/api/electron_api_web_contents.cc"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"263652545862719024259892432036565024449",
"261832269141785916386151165807289484275",
"97255024284230196527714781681060040644",
"62655028987936040239214713684370885790"
]
},
"signature_version": "v1",
"source": "https://github.com/electron/electron/commit/0cbdf2f0375466d701aa393c92e0ec29eb89ea6c",
"id": "CVE-2026-70599-fb9e7d4d"
}
]