Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34777

Опубликовано: 03 апр. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, when an iframe requests fullscreen, pointerLock, keyboardLock, openExternal, or media permissions, the origin passed to session.setPermissionRequestHandler() was the top-level page's origin rather than the requesting iframe's origin. Apps that grant permissions based on the origin parameter or webContents.getURL() may inadvertently grant permissions to embedded third-party content. The correct requesting URL remains available via details.requestingUrl. Apps that already check details.requestingUrl are not affected. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0.

A flaw was found in Electron, a framework for building desktop applications. When an embedded iframe requests permissions, such as for fullscreen or media access, the framework incorrectly provides the origin of the main page instead of the requesting iframe's origin. This vulnerability allows a remote attacker, through malicious embedded content, to potentially gain unauthorized permissions. This could lead to unintended information disclosure or other unauthorized actions by the third-party content within the application. The correct requesting URL remains available via details.requestingUrl. Apps that already check details.requestingUrl are not affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Podman Desktoppodman-desktop-macos-1-0Fix deferred
Red Hat Build of Podman Desktoppodman-desktop-windows-1-0Fix deferred
Red Hat Build of Podman Desktop - Tech Previewrhdesktop/rh-podman-desktop-ext-openshift-local-rhel10Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-346
https://bugzilla.redhat.com/show_bug.cgi?id=2455022Electron: Electron: Unauthorized permission granting and information disclosure via incorrect iframe origin

EPSS

Процентиль: 2%
0.00122
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
4 месяца назад

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0, when an iframe requests fullscreen, pointerLock, keyboardLock, openExternal, or media permissions, the origin passed to session.setPermissionRequestHandler() was the top-level page's origin rather than the requesting iframe's origin. Apps that grant permissions based on the origin parameter or webContents.getURL() may inadvertently grant permissions to embedded third-party content. The correct requesting URL remains available via details.requestingUrl. Apps that already check details.requestingUrl are not affected. This issue has been patched in versions 38.8.6, 39.8.1, 40.8.1, and 41.0.0.

CVSS3: 5.4
debian
4 месяца назад

Electron is a framework for writing cross-platform desktop application ...

CVSS3: 5.4
github
4 месяца назад

Electron: Incorrect origin passed to permission request handler for iframe requests

EPSS

Процентиль: 2%
0.00122
Низкий

5.4 Medium

CVSS3