Disclosure summary
### Impact On macOS, Electron bundles the Squirrel.Mac auto-update framework, whose privileged `ShipIt` helper performs the final step of an update as root. A local attacker could cause that helper to overwrite a different application's files, as root, instead of the app that started the update. Exploitation requires local access to the machine. Apps are only affected on macOS if they ship Squirrel.Mac-based auto-updates. Apps on other platforms, or that do not use Squirrel.Mac auto-updates, are not affected. ### Workarounds There are no app side workarounds, you must update to a patched version of Electron. ### Fixed Versions * `42.0.0-beta.2` * `41.10.5` * `39.8.10` ### For more information If you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org)
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-vv43-5jgx-7qv8
Open original source · Updated Sep 29, 2026
Electron: Local race condition in Squirrel.Mac update installation on macOS
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | electron | < 39.8.10 | 39.8.10 |
| npm | electron | >= 40.0.0-alpha.1, < 41.10.5 | 41.10.5 |
| npm | electron | >= 42.0.0-alpha.1, < 42.0.0-beta.2 | 42.0.0-beta.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-29T14:06:59-04:00
MODIFIED 2026-09-29T14:07:01-04:00
INGESTED 2026-10-06T11:43:08-04:00