THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jm7p-cc5g-qwxx (medium) — Electron: Parent process code-sign check is spoofable

[GHSA] GHSA-jm7p-cc5g-qwxx (medium) — Electron: Parent process code-sign check is spoofable

medgithub_advisoriesPublished 2026-08-05

GHSA-jm7p-cc5g-qwxx Severity: medium CVE: CVE-2026-70597

Electron: Parent process code-sign check is spoofable

### Impact On macOS, the check Electron uses to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enable the fuse-based hardening restricting `ELECTRON_RUN_AS_NODE` and `NODE_OPTIONS` to same-signed parents rely on this check; a loca

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jm7p-cc5g-qwxx