THREAT OPS › Threat News › [GHSA] GHSA-jm7p-cc5g-qwxx (medium) — Electron: Parent process code-sign check is spoofable
[GHSA] GHSA-jm7p-cc5g-qwxx (medium) — Electron: Parent process code-sign check is spoofable
GHSA-jm7p-cc5g-qwxx Severity: medium CVE: CVE-2026-70597
Electron: Parent process code-sign check is spoofable
### Impact On macOS, the check Electron uses to confirm it was launched by a same-signed parent process could be bypassed by a local process. Apps that enable the fuse-based hardening restricting `ELECTRON_RUN_AS_NODE` and `NODE_OPTIONS` to same-signed parents rely on this check; a loca
Indicators of compromise
- CVE-2026-70597cve
- security@electronjs.orgemail
Original source: https://github.com/advisories/GHSA-jm7p-cc5g-qwxx