Responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI: true but without corsEnabled: true could be read cross-origin by web content. This completes the fix for CVE-2026-70604.
Apps are only affected if they register such a scheme, serve it through one of those handlers, and load untrusted content. Apps that set corsEnabled: true, or that do not load untrusted content, are not affected.
Set corsEnabled: true on the scheme, or do not load untrusted content in windows that can reach it.
44.0.0-beta.543.4.142.9.241.10.6If you have any questions or comments about this advisory, email us at security@electronjs.org
{
"cwe_ids": [
"CWE-346"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-29T18:04:24Z",
"nvd_published_at": null,
"severity": "HIGH"
}