THREAT OPS › Threat News › [GHSA] GHSA-ff2p-hmqr-hxm4 (medium) — Electron: contextBridge object copy honors prototype setters
[GHSA] GHSA-ff2p-hmqr-hxm4 (medium) — Electron: contextBridge object copy honors prototype setters
GHSA-ff2p-hmqr-hxm4 Severity: medium CVE: CVE-2026-70610
Electron: contextBridge object copy honors prototype setters
### Impact Objects copied across the `contextBridge` boundary from untrusted content could carry an attacker-influenced prototype, enabling prototype-pollution-style attacks against preload code despite context isolation being enabled.
Apps are only affected if their preload cod
Indicators of compromise
- CVE-2026-70610cve
- security@electronjs.orgemail
Original source: https://github.com/advisories/GHSA-ff2p-hmqr-hxm4