THREAT OPS › Threat News › [GHSA] GHSA-h7rp-cf8h-j98x (high) — Electron: Context isolation bypass via Function.prototype.bind hijack
[GHSA] GHSA-h7rp-cf8h-j98x (high) — Electron: Context isolation bypass via Function.prototype.bind hijack
GHSA-h7rp-cf8h-j98x Severity: high CVE: CVE-2026-70601
Electron: Context isolation bypass via Function.prototype.bind hijack
### Impact Apps that expose Promise-returning functions to web content via `contextBridge` may be vulnerable to a context isolation bypass. Untrusted web content could obtain access to the isolated preload world and, through it, every capability the preload script has. In
Indicators of compromise
- CVE-2026-70601cve
- security@electronjs.orgemail
Original source: https://github.com/advisories/GHSA-h7rp-cf8h-j98x