THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-m55f-7gqj-fr98 (medium) — Electron: Extension tab APIs operate across session boundaries

[GHSA] GHSA-m55f-7gqj-fr98 (medium) — Electron: Extension tab APIs operate across session boundaries

medgithub_advisoriesPublished 2026-08-05

GHSA-m55f-7gqj-fr98 Severity: medium CVE: CVE-2026-70602

Electron: Extension tab APIs operate across session boundaries

### Impact Extension tab and scripting APIs were not scoped to the extension's own `session`. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session.

Apps are only affected if they load Chrome

Indicators of compromise

Original source: https://github.com/advisories/GHSA-m55f-7gqj-fr98