THREAT OPS › Threat News › [GHSA] GHSA-m55f-7gqj-fr98 (medium) — Electron: Extension tab APIs operate across session boundaries
[GHSA] GHSA-m55f-7gqj-fr98 (medium) — Electron: Extension tab APIs operate across session boundaries
GHSA-m55f-7gqj-fr98 Severity: medium CVE: CVE-2026-70602
Electron: Extension tab APIs operate across session boundaries
### Impact Extension tab and scripting APIs were not scoped to the extension's own `session`. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session.
Apps are only affected if they load Chrome
Indicators of compromise
- CVE-2026-70602cve
- security@electronjs.orgemail
Original source: https://github.com/advisories/GHSA-m55f-7gqj-fr98