AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-102672.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 29, 2026

Disclosure summary

### Impact On macOS, Electron bundles the Squirrel.Mac auto-update framework, whose privileged `ShipIt` helper performs the final step of an update as root. A local attacker could cause that helper to overwrite a different application's files, as root, instead of the app that started the update. Exploitation requires local access to the machine. Apps are only affected on macOS if they ship Squirrel.Mac-based auto-updates. Apps on other platforms, or that do not use Squirrel.Mac auto-updates, are not affected. ### Workarounds There are no app side workarounds, you must update to a patched version of Electron. ### Fixed Versions * `42.0.0-beta.2` * `41.10.5` * `39.8.10` ### For more information If you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org)

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-vv43-5jgx-7qv8

Open original source · Updated Sep 29, 2026

Electron: Local race condition in Squirrel.Mac update installation on macOS

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
npmelectron< 39.8.1039.8.10
npmelectron>= 40.0.0-alpha.1, < 41.10.541.10.5
npmelectron>= 42.0.0-alpha.1, < 42.0.0-beta.242.0.0-beta.2

Original records & references

PUBLISHED 2026-09-29T14:06:59-04:00
MODIFIED 2026-09-29T14:07:01-04:00
INGESTED 2026-10-06T11:43:08-04:00