THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h7rp-cf8h-j98x (high) — Electron: Context isolation bypass via Function.prototype.bind hijack

[GHSA] GHSA-h7rp-cf8h-j98x (high) — Electron: Context isolation bypass via Function.prototype.bind hijack

medgithub_advisoriesPublished 2026-08-05

GHSA-h7rp-cf8h-j98x Severity: high CVE: CVE-2026-70601

Electron: Context isolation bypass via Function.prototype.bind hijack

### Impact Apps that expose Promise-returning functions to web content via `contextBridge` may be vulnerable to a context isolation bypass. Untrusted web content could obtain access to the isolated preload world and, through it, every capability the preload script has. In

Indicators of compromise

Original source: https://github.com/advisories/GHSA-h7rp-cf8h-j98x