THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9pf5-hg6p-4pwp (medium) — Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin

[GHSA] GHSA-9pf5-hg6p-4pwp (medium) — Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin

medgithub_advisoriesPublished 2026-08-05

GHSA-9pf5-hg6p-4pwp Severity: medium CVE: CVE-2026-70599

Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin

### Impact For serial-port and media (camera / microphone) permission checks made from an iframe, the `requestingOrigin` passed to `session.setPermissionCheckHandler` was the top-level frame's origin rather than the requesting frame's. Origin-

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9pf5-hg6p-4pwp